WordPress users beware – experts claim websites are being hijacked using a critical flaw in the popular Everest Forms Pro plugin


  • Actively Exploited Critical RCE Vulnerability in Everest Forms Pro (CVE-2026-3300).
  • Attackers create rogue admin account “diksimarina” via PHP injection
  • Almost 30,000 takeover attempts blocked; administrators are encouraged to patch and block key IPs

Security researchers are warning of an ongoing hacking campaign targeting certain WordPress sites using a popular plugin tool.

Wordfence has claimed that Everest Forms Pro, a popular WordPress plugin allegedly used to create contract, registration, payment and other application forms, had a Critical Severity vulnerability that allowed malicious actors to completely take over websites.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top