Multiple outlets report that attackers are actively exploiting a critical vulnerability in the WordPress plugin Everest Forms Pro to compromise websites. The flaw is identified as CVE-2026-3300, which is rated CVSS 9.8 for remote code execution impact. The vulnerability allows threat actors to execute arbitrary code on affected sites, enabling full site takeover. The Hacker News reports that the bug affects all versions of Everest Forms Pro up to and including version 1.9.12, and that exploitation is occurring against sites in the wild. Infosecurity Magazine adds that the exploitation can be used to create rogue WordPress administrative accounts, further facilitating persistence and control after initial compromise.
Both reports frame the issue as an actively exploited high-severity plugin flaw affecting WordPress installations. The Hacker News indicates Everest Forms Pro has roughly 4,000 active installations, underscoring a relatively limited but non-trivial exposure. The sources also reference that a patch exists, implying remediation is available, though exact release details are not fully provided in the excerpts.