Critical Everest Forms Pro Flaw Exploited
Hackers are actively exploiting a critical flaw in Everest Forms Pro to seize full control of WordPress sites.
CVE-2026-3300 is a PHP code injection flaw in the Calculation Addon's eval() function. Attackers inject malicious PHP through form fields on any site using the Complex Calculation feature. CVSS 9.8, actively exploited in the wild.
Affects Everest Forms Pro versions up to and including 1.9.12, patched in 1.9.13.
Widespread exploitation observed since April 13, 2026. No verified site count available.
