Attention WordPress users: Experts say sites are being hacked using a critical flaw in the popular Everest Forms Pro plugin.


  • Critical RCE vulnerability in Everest Forms Pro (CVE‑2026‑3300) actively exploited
  • Attackers create a malicious “diksimarina” administrator account via PHP injection
  • Nearly 30,000 redemption attempts blocked; administrators are asked to fix and block key IP addresses

Security researchers are warning of an ongoing hacking campaign targeting some WordPress websites using a popular plugin tool.

Wordfence claimed that Everest Forms Pro, a popular WordPress plugin, was allegedly used to create contract, registration, payment, and other application forms, and contained a critical severity vulnerability that allowed malicious actors to take over sites entirely.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top