FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Critical RCE Vulnerability CVE-2026-3300 in Everest Forms Pro

A critical Remote Code Execution (RCE) vulnerability, tracked as CVE-2026-3300, is currently being exploited in the wild against the Everest Forms Pro WordPress plugin. The flaw, carrying a CVSS score of 9.8, stems from improper input validation within the plugin's "complex calculation" feature. Unauthenticated attackers can leverage this vulnerability to execute arbitrary code, facilitating complete administrative takeover of affected WordPress environments. With approximately 4,000 active installations vulnerable, threat actors are utilizing specific payload patterns to trigger the calculation engine, leading to webshell deployment, unauthorized user creation, and potential data exfiltration. Immediate patching to version 1.9.13 or higher is required to mitigate this high-risk threat.


LINK COPIED TO CLIPBOARD