WordPress users beware — experts claim sites are being hijacked using a critical flaw in popular Everest Forms Pro plugin



  • Critical RCE flaw in Everest Forms Pro (CVE‑2026‑3300) actively exploited
  • Attackers create rogue admin account “diksimarina” via PHP injection
  • Nearly 30,000 takeover attempts blocked; admins urged to patch and block key IPs

Security researchers are warning of an ongoing hacking campaign targeting certain WordPress websites using a popular plugin tool.

Wordfence has claimed Everest Forms Pro, a popular WordPress plugin, was allegedly being used to create contract, registration, payment, and other application forms, carried a critical-severity vulnerability that allowed malicious actors to take over the sites entirely.

https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img