Hackers are actively exploiting a critical unauthenticated remote code execution vulnerability, tracked as CVE-2026-3300, in the Everest Forms Pro WordPress plugin to create unauthorized administrator accounts on websites.
Key Points
- The vulnerability affects Everest Forms Pro versions 1.9.12 and earlier by improperly sanitizing input in the Complex Calculation feature.
- Attackers inject malicious PHP code via form fields to execute commands on the server, bypassing existing security filters.
- Wordfence reports that attackers are using this flaw to create rogue administrator accounts under the username "diksimarina."
- A security patch was released by the plugin developer on March 18 to address the vulnerability.
- Active exploitation began on April 13, with the Wordfence firewall blocking over 29,300 malicious attempts.
- Administrators should update the plugin immediately and audit user accounts for suspicious activity or unauthorized administrative access.