WordPress Users Beware: Experts Claim Sites Are Being Hijacked Using a Critical Flaw in the Popular Everest Forms Pro Plugin



  • Critical RCE Flaw in Everest Forms Pro (CVE‑2026‑3300) Actively Exploited
  • Attackers create fraudulent “diksimarina” administrator account via PHP injection
  • Nearly 30,000 acquisition attempts blocked; Administrators urged to patch and block key IPs

Security researchers are warning of an ongoing hacking campaign targeting certain WordPress websites using a popular plugin tool.

Wordfence has claimed that Everest Forms Pro, a popular WordPress plugin, which was allegedly being used to create contracts, registrations, payments and other application forms, had a critical severity vulnerability that allowed malicious actors to take over sites entirely.

Leave a Comment

Your email address will not be published. Required fields are marked *