Vulnerability Advisory
CVE-2026-3300
Hackers are actively exploiting CVE-2026-3300, a CVSS 9.8 flaw in Everest Forms Pro WordPress plugin. 29,300+ attacks blocked. If you run WordPress, check your plugins right now.
Severity
critical
CVSS Score
9.6 / 10
Fix Status
Patch available
Exploitation
Actively exploited
Published
Jun 5, 2026
Key Facts
- ›CVE-2026-3300 scores 9.8 on the CVSS scale and affects every release of Everest Forms Pro up to and including 1.9.12 — a commercial form builder with roughly 4,000 active WordPress installations
- ›The flaw requires zero authentication — any visitor to your site can exploit it by submitting a crafted value in a contact form, giving them complete control of your server
- ›Despite a patch being released on March 18, 2026, threat actors began actively targeting unpatched installations on April 13, 2026 and have not stopped since
- ›Update Everest Forms Pro to version 1.9.13 immediately — if you cannot update right now, disable the Complex Calculation feature on all forms as a temporary measure
Full Analysis
CVE-2026-3300: Critical WordPress Plugin Flaw Actively Exploited — 29,300 Attack Attempts Blocked
Deep-dive: technical breakdown, real-world impact, complete remediation steps, and expert context.
Read the full report →