Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPress website.

Threat actors are actively exploiting CVE-2026-3300, a critical RCE vulnerability (CVSS 9.8) in Everest Forms Pro WordPress plugin (4,000+ installs).

Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPress website.

Hackers have been exploiting a remote code execution vulnerability in the Everest Forms Pro plugin to take over WordPress sites.

Una vulnerabilità critica in Everest Forms Pro consente il controllo completo dei siti WordPress non aggiornati.