# Critical Everest Forms Vulnerability Enables Mass WordPress Takeovers—Exploited for Two Months


## The Threat


A critical remote code execution vulnerability in the widely-deployed Everest Forms Pro WordPress plugin has been actively exploited in the wild for two months, allowing unauthenticated attackers to execute arbitrary PHP code and seize control of vulnerable websites. The flaw resides in the plugin's Complex Calculation feature, a tool designed to perform mathematical operations within form submissions.


The vulnerability stems from improper input validation and escaping. When a form field is configured to use the Complex Calculation feature, user-supplied values are processed through a vulnerable function that fails to escape single quotes and other special characters. An attacker can exploit this by injecting a single quote followed by malicious PHP code and a comment character into any string-type form field (text, email, URL, select, or radio). The injected code is then concatenated into a PHP string and executed server-side without sanitization—bypassing the plugin's standard input sanitization layer.


Everest Forms is installed on more than 100,000 WordPress websites, making this vulnerability a significant vector for mass site compromise. Threat actors have leveraged this flaw to create unauthorized administrative accounts, deploy web shells, and establish persistent access to compromised systems. The exploitation campaign began in April 2026, weeks after the vendor released a patch in March.


## Severity and Impact


| Attribute | Details |

|-----------|---------|

| CVE Identifier | CVE-2026-3300 |

| CVSS v3.1 Score | 9.8 (Critical) |

| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |

| Attack Vector | Network |

| Attack Complexity | Low |

| Privileges Required | None |

| User Interaction | None |

| Affected Components | Everest Forms Pro Complex Calculation Feature |

| CWE | CWE-94 (Improper Control of Generation of Code) |


The 9.8 CVSS score reflects the severity: no authentication required, low attack complexity, and complete compromise of confidentiality, integrity, and availability. An attacker with only network access can trigger arbitrary code execution with a single crafted form submission.


## Affected Products


Everest Forms Pro:

  • Versions prior to 1.9.13
  • All installations using the Complex Calculation feature are vulnerable
  • Confirmed affected on 100,000+ WordPress sites

  • The vulnerability affects any WordPress deployment running an unpatched version of Everest Forms Pro that includes forms configured with the Complex Calculation feature enabled.


    ## Mitigations


    Immediate Actions:

    1. Update immediately: Upgrade Everest Forms Pro to version 1.9.13 or newer without delay

    2. Audit administrative accounts: Search for unauthorized administrators, particularly accounts named 'diksimarina' or using the email '[email protected]'

    3. Review access logs: Examine WordPress login attempts and administrator account creation events between April 13 and the present

    4. Check for web shells: Scan the WordPress installation directory and uploads folder for suspicious files, particularly PHP files not associated with legitimate plugins or themes


    Detection and Response:

  • Monitor database audit logs for unexpected user account creation or privilege escalation
  • Review web server access logs for POST requests to wp-admin/user-new.php from unknown IP addresses
  • Enable WordPress security logging to track unauthorized access attempts
  • Consider deploying a WordPress security plugin if not already in place

  • Network-Level Controls:

  • Restrict direct access to WordPress admin interfaces via network firewall rules
  • Implement rate limiting on form submissions to reduce exploitation attempts
  • Monitor outbound HTTP/HTTPS traffic from the web server for indicators of web shell communication

  • Post-Incident:

    If compromise is suspected, change all administrative credentials, audit database users and their permissions, and consider a full security audit by qualified professionals.


    ## References


  • Defiant Security Advisory: [Everest Forms Pro RCE Vulnerability](https://www.defiant.com/) (original disclosure)
  • WordPress Plugin Directory: [Everest Forms](https://wordpress.org/plugins/everest-forms/)
  • CVE Details: [CVE-2026-3300](https://nvd.nist.gov/vuln/detail/CVE-2026-3300)

  • ---


    ## HackWire Analysis


    This vulnerability exemplifies a dangerous pattern in the WordPress ecosystem: form builders are attractive targets because they sit at the intersection of public access (anyone can submit a form) and sensitive functionality (data processing). Everest Forms is the third major form plugin compromised in similar fashion over the past year, following vulnerabilities in Forminator and WPForms derivatives.


    What's particularly concerning is the exploitation timeline. Patches shipped in March, but exploitation didn't accelerate until April 13—suggesting attackers invested weeks in weaponizing the vulnerability after it became patchable (an implicit signal that a fix existed). The 29,000+ blocked exploitation attempts represent only what Defiant's own security layer detected; real-world attack volume is likely far higher. Many unprotected sites are probably already compromised without the site owners knowing.


    The 'diksimarina' indicator is a gift for defenders—automated account audits and log searches can identify likely compromises. But this low-sophistication naming pattern also suggests script-kiddie level threats at scale, not surgical APT operations. That means volume attacks targeting indiscriminate victim lists, which is both good and bad: less targeted persistence, but higher overall victim count.


    The deeper issue: form plugins process user input destined for complex operations (calculations, conditional logic, payment processing). The attack surface is inherently high-trust. Everest Forms' failure wasn't exotic—it was vanilla input validation done incorrectly. Any form builder with a calculation engine should be treated as a critical dependency and audited frequently. A 100,000-site blast radius from a three-week-old patch delay is unacceptable in 2026.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)