News

Everest Forms Pro WordPress Flaw is Handing Attackers Admin Access

  • Pierluigi Paganini--Securityaffairs.com
  • published date: 2026-06-08 14:11:44 UTC

Hackers exploit CVE-2026-3300 in Everest Forms Pro to inject PHP via form fields, creating rogue admin accounts. 29,300 attempts blocked. Researcher h0xilo submitted a flaw in Everest Forms Pro for WordPress, tracked as CVE-2026-3300, to Wordfence’s bug bount…

Everest Forms Pro WordPress Flaw is Handing Attackers Admin Access Researcher h0xilo submitted a flaw in Everest Forms Pro for WordPress, tracked as CVE-2026-3300, to Wordfence’s bug bounty program … [+3982 chars]