<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites-n1yehrb99" -->

---
title: Critical Everest Forms Pro flaw exploited to take over...
description: A critical unauthenticated remote code execution vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin is being actively exploited in the...
canonical: https://daily.dev/posts/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites-n1yehrb99
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Critical Everest Forms Pro flaw exploited to take over WordPress sites | daily.dev
og:description: A critical unauthenticated remote code execution vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin is being actively exploited in the...
og:url: https://daily.dev/posts/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites-n1yehrb99
og:image: https://api.daily.dev/og/posts/N1yEHRB99.png
og:image:alt: Critical Everest Forms Pro flaw exploited to take over WordPress sites
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Critical Everest Forms Pro flaw exploited to take over WordPress sites

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

A critical unauthenticated remote code execution vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin is being actively exploited in the wild. The flaw exists in the plugin's Complex Calculation feature, which passes user input through PHP's eval() function without properly escaping single quotes, allowing attackers to inject arbitrary PHP code. Exploitation has been observed creating rogue administrator accounts with the username 'diksimarina'. Wordfence has blocked over 29,300 exploitation attempts since April 13. A patch was released on March 18 in response to a February disclosure. Site admins are urged to update immediately, block known malicious IPs, and audit administrator accounts and logs for signs of compromise.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites>

## Similar posts on daily.dev

- [Hackers exploit critical flaw in Ninja Forms WordPress plugin](https://daily.dev/posts/hackers-exploit-critical-flaw-in-ninja-forms-wordpress-plugin-vf9rfivjr) · BleepingComputer · 5 upvotes · 0 comments
- [Critical Kirki flaw exploited to hijack WordPress admin accounts](https://daily.dev/posts/critical-kirki-flaw-exploited-to-hijack-wordpress-admin-accounts-ym6h9qcps) · BleepingComputer · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#php](https://daily.dev/tags/php), [#wordpress](https://daily.dev/tags/wordpress)

[View this post on daily.dev](https://daily.dev/posts/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites-n1yehrb99)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Critical Everest Forms Pro flaw exploited to take over WordPress sites","url":"https://daily.dev/posts/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites-n1yehrb99","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites-n1yehrb99"},"datePublished":"2026-06-06T14:19:39.081Z","dateModified":"2026-06-06T14:20:10.942Z","description":"A critical unauthenticated remote code execution vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin is being actively exploited in the...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/fb8940c74359e1920ac162b9b6e594a8?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/fb8940c74359e1920ac162b9b6e594a8?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites-n1yehrb99","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,php,wordpress","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Critical Everest Forms Pro flaw exploited to take over WordPress sites"}]}
```

