Serious Vulnerability in Everest Forms Pro Used to Compromise WordPress Sites

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Critical Vulnerability in Everest Forms Pro Plugin Exploited by Cybercriminals

Hackers are vigorously exploiting a severe vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, enabling them to seize complete control of WordPress websites.

This security flaw affects all versions prior to 1.9.12 and can be exploited without any authentication to execute arbitrary code on the server.

Everest Forms Pro serves as a commercial extension for the WordPress form builder known as Everest Forms, widely utilized for creating contact forms, registration interfaces, and other bespoke application forms.

The vulnerability, identified as CVE-2026-3300, resides within the plugin’s Complex Calculation feature, which accepts values through form fields and interpolates them into a PHP code string. This is subsequently executed using PHP’s ‘eval()’ function.

Despite the presence of the ‘sanitize_text_field()’ function, which ostensibly sanitizes user inputs, it neglects to escape certain characters, including single quotes (‘) that could manipulate PHP syntax.

Consequently, an attacker may terminate the intended string, insert arbitrary PHP code, and effectively comment out the remainder of the generated code, thereby accomplishing code execution on the server.

Telemetry data gleaned from the Wordfence firewall and malware scanner indicates that this vulnerability is fervently being exploited in the wild to establish illicit administrator accounts.

“The attacker inputs a value in a text field starting with a single quote to close the enclosing string literal, followed by a PHP statement that invokes wp_insert_user() to create a new administrator account with the username ‘diksimarina’,” elucidates a report from Wordfence.

“The consequent // comment marker guarantees that the rest of the generated PHP code, including the closing quote, is treated as a comment, thus avoiding a syntax error.”

“Upon processing the form and evaluating the calculation, the injected PHP code is executed, culminating in the creation of the malicious administrator account.”

With administrator-level access, attackers can execute high-risk operations on compromised websites, including content manipulation, plugin and theme installations, backdoor embedding, and database access.

The vulnerability was reported by researcher h0xilo to Wordfence in February, and a patch to rectify the issue was disseminated by Everest Forms’ developers on March 18.

Wordfence reports that these exploitation attempts primarily emanate from two specific IP addresses: 202.56.2[.]126 and 209.146.60.26, recommending that defenders block these addresses.

Furthermore, Wordfence’s report enumerates several offending IP addresses as indicators of compromise (IOCs).

A computer monitor displaying the Wordfence security dashboard sits on a desk in a server room, with a keyboard and coffee cup nearby.

Website administrators are also urged to meticulously examine log files and administrator accounts for any suspicious activities, particularly those containing the username “diksimarina.”

Source link: Bleepingcomputer.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading