Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityinternet-facing-service-vulnerabilitywidely-deployed-product-advisorypersistence-method

Active Exploitation of Everest Forms Pro RCE Creates Rogue WordPress Admins

Updated 14d agoFirst seen Jun 4, 20268 sources

Attackers are actively exploiting CVE-2026-3300, a critical unauthenticated remote code execution flaw in the Everest Forms Pro WordPress plugin, to fully compromise vulnerable sites. The bug affects versions through 1.9.12 and was fixed in 1.9.13. It stems from the plugin’s Complex Calculation feature, where user-controlled input in process_filter() is concatenated into PHP code and executed with eval(), allowing arbitrary PHP injection through crafted form submissions, often via the /wp-admin/admin-ajax.php endpoint.

Wordfence reported exploitation beginning on April 13 and escalating into mass attacks, with more than 29,300 exploit attempts blocked overall and over 17,900 on May 16 alone. A recurring payload creates a rogue administrator account named diksimarina, giving attackers persistent access to upload webshells, install backdoors, alter site content, and potentially pivot deeper into the hosting environment. Defenders are being urged to upgrade immediately to 1.9.13 or later, audit WordPress administrator accounts for unauthorized users, and review logs for suspicious requests and known malicious IP activity.

Share:
Active Exploitation of Everest Forms Pro RCE Creates Rogue WordPress Admins
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
May 16, 20261mo ago

Mass exploitation spike hits Everest Forms Pro targets

Telemetry showed a major surge in exploitation on May 16, 2026, with more than 17,900 exploit requests blocked that day alone. Reports said attackers were often using payloads to create a WordPress administrator account named "diksimarina."

Everest Forms Pro Flaw Faces Active WordPress Exploitation
Apr 13, 20262mo ago

Attackers begin exploiting Everest Forms Pro flaw

Wordfence observed exploitation activity targeting CVE-2026-3300 beginning on April 13, 2026. The attacks targeted unpatched WordPress sites and commonly attempted to create rogue administrator accounts for persistence.

Everest Forms Pro Flaw Faces Active WordPress Exploitation
Mar 30, 20263mo ago

CVE-2026-3300 publicly disclosed

The Everest Forms Pro remote code execution vulnerability was publicly disclosed after the patch release. Reporting described the flaw as critical, with a CVSS score of 9.8, and tied it to improper input handling in the plugin's calculation functionality.

Hackers Actively Exploiting WordPress Plugin Vulnerability to Inject PHP code
Mar 18, 20263mo ago

Everest Forms Pro patch released for CVE-2026-3300

A fix for the critical unauthenticated remote code execution flaw CVE-2026-3300 in Everest Forms Pro was released in version 1.9.13. The vulnerability affected versions up to 1.9.12 and involved unsafe use of eval() in the Complex Calculation feature.

Hackers Actively Exploiting WordPress Plugin Vulnerability to Inject PHP code
Aug 1, 202511mo ago

Sansec reports GorgonAgora fake storefront skimming campaign

Sansec described the GorgonAgora operation as active since August 2025, using 5,714 fake .shop storefronts impersonating major brands to steal payment card data. The campaign reportedly used a fake Stripe iframe and infrastructure tied to a server in Moldova to relay 3D Secure challenges and evade detection.

Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
Affected products
4 linked
Everest Forms ProWordfenceWordpressEverest Forms
Organizations
6 linked
WordfenceEverest FormsWpeverestBleepingComputerSecurity AffairsEverest Forms developer
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Active Exploitation of Everest Forms Pro RCE Creates Rogue WordPress Admins | Mallory