CT
CyberTimes
HomeThreat WatchCVE-2026-3300
Vulnerability Advisory

CVE-2026-3300

Hackers are actively exploiting CVE-2026-3300, a CVSS 9.8 flaw in Everest Forms Pro WordPress plugin. 29,300+ attacks blocked. If you run WordPress, check your plugins right now.

Severity
critical
CVSS Score
9.6 / 10
Fix Status
Patch available
Exploitation
Actively exploited
Published
Jun 5, 2026

Key Facts

  • CVE-2026-3300 scores 9.8 on the CVSS scale and affects every release of Everest Forms Pro up to and including 1.9.12 — a commercial form builder with roughly 4,000 active WordPress installations
  • The flaw requires zero authentication — any visitor to your site can exploit it by submitting a crafted value in a contact form, giving them complete control of your server
  • Despite a patch being released on March 18, 2026, threat actors began actively targeting unpatched installations on April 13, 2026 and have not stopped since
  • Update Everest Forms Pro to version 1.9.13 immediately — if you cannot update right now, disable the Complex Calculation feature on all forms as a temporary measure

Full Analysis

CVE-2026-3300: Critical WordPress Plugin Flaw Actively Exploited — 29,300 Attack Attempts Blocked

Deep-dive: technical breakdown, real-world impact, complete remediation steps, and expert context.

Read the full report →
← All threat reportsAll articles