Everest Forms Pro WordPress Flaw is Handing Attackers Admin Access


Everest Forms Pro WordPress Flaw is Handing Attackers Admin Access

Pierluigi Paganini
June 08, 2026

Hackers exploit CVE-2026-3300 in Everest Forms Pro to inject PHP via form fields, creating rogue admin accounts. 29,300 attempts blocked.

Researcher h0xilo submitted a flaw in Everest Forms Pro for WordPress, tracked as CVE-2026-3300, to Wordfence’s bug bounty program and earned $325 for it. WPEverest patched the flaw on March 18. Wordfence published a full disclosure on March 30, but the exploitation started on April 13. That’s a 26-day window between patch and first attack, which sounds manageable until you realize thousands of sites running Everest Forms Pro still haven’t updated, and the attackers noticed.

The vulnerability lives in the plugin’s Complex Calculation feature. The culprit is a function called process_filter() inside the Calculation Addon, which takes values submitted through form fields and builds them into a PHP code string before passing that string to eval().

“This is due to the Calculation Addon’s process_filter() function concatenating user-submitted form field values into a PHP code string without proper escaping before passing it to eval().” reads the report published by Wordfence. “The sanitize_text_field() function applied to input does not escape single quotes or other PHP code context characters.”

The consequence is that any string-type form field, text, email, URL, select, or radio, becomes an injection point on any form using Complex Calculation.

No credentials needed. The attacker submits a crafted value through a public-facing form: a single quote to break out of the string literal, followed by arbitrary PHP code, followed by // to comment out the rest of the generated code and prevent a syntax error. The server processes the form, the calculation runs, and the injected PHP executes alongside it. The most common payload observed in Wordfence’s blocked requests is surgical in its simplicity.

“The attacker submits a value for a text field that begins with a single quote to close the wrapping string literal, followed by a PHP statement that calls wp_insert_user() to create a new administrator account with the username ‘diksimarina’.” continues the report. “The trailing // comment marker ensures the rest of the generated PHP code, including the closing quote, is treated as a comment and does not cause a syntax error.”

The server echoes back either ADMINCREATED or ADMINEXISTS depending on whether the account already existed, which tells the attacker exactly what happened. Subtle it is not.

Once that administrator account exists, the attacker can log in and do anything: upload web shells, modify themes or plugins, install backdoors, read and exfiltrate database contents. It’s full site ownership, delivered through a contact form. Wordfence recorded 29,300 blocked exploit attempts since public disclosure, with one particularly aggressive day standing out. On May 16, over 17,900 attempts were blocked in a single 24-hour period. One IP address, 202.56.2.126, accounts for over 26,300 of the total blocked requests on its own.

“Our threat intelligence indicates that attackers started actively targeting this vulnerability on April 13th, 2026, with mass exploitation occurring on May 16th, 2026. The Wordfence firewall has already blocked over 29,300 exploit attempts targeting this vulnerability.” states Wordfence.

The experts pointed out that Wordfence Premium, Care, and Response users had a firewall rule in place since February 27, before public disclosure. Free Wordfence users got the same rule on March 29. Neither group is safe from future attempts if the underlying plugin isn’t updated.

The fix is version 1.9.13, out since March 18. Update immediately. After updating, open your WordPress user list and look for any administrator account named “diksimarina” or registered to [email protected]. If you find one, the site is compromised: audit for web shells, check recently modified files across themes and plugins, rotate all credentials, and treat the database as potentially read. Also review server logs for requests originating from 202.56.2.126, 209.146.60.26, 15.235.166.18, 2402:1f00:8000:800::40db, and 185.78.165.153.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, WordPress)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


If you are a book purist, you might scoff when I recommend an e-reader instead of buying physical books, and I won’t blame you. The allure of the smell of pages, the weight of the book in my hands, the whole ritual, is hard to resist. 

However, if you allow me some leeway to convince you, there’s a strong argument to be made against physical books and in favor of using e-readers. So let me make the case for e-readers, because once you understand what you’ve been missing, it’s hard to go back.

Your entire library fits in your bag

This is the most obvious advantage, but it doesn’t get enough credit. I always read more than one book at a time, and carrying two or three physical books around is not realistic. Thick books alone are a chore to carry.

With an e-reader, you carry hundreds of books in a slim package. Switching between titles takes a second. If you travel frequently, this alone is reason enough to make the switch.

A thousand-page hardcover is great for your bookshelf but terrible for your commute.

Fat books are a workout, not a reading experience

If, like me, you are into fantasy books, you know they can be a behemoth to handle. You have to constantly shift how you’re holding it, find a way to keep it open, and somehow also stay comfortable. Thin books are fine, but the moment a book crosses a certain thickness, it starts working against you.

An e-reader weighs the same regardless of whether you’re reading a short novel or a massive fantasy series. That’s it. Whether I am reading The Count of Monte Cristo or the next book in Brandon Sanderson’s The Stormlight Archive series, my Supernote Nomad remains the same. 

Reading at night without waking anyone up

I do a lot of my reading at night, and this is where physical books completely fall apart for me. Lamps and book lights never feel comfortable. The light is never quite right, and if you share a room with someone, the whole setup becomes a problem.

Most e-readers, including Kindles, have a built-in backlight that you can dim to whatever level feels right. You can even switch to warm light mode, making it easier on your eyes. 

I’ve read at 3 AM with the brightness all the way down, and it felt completely natural. No lamp and no squinting required. 

Look up any word without losing your place

English is not my first language, and even for native speakers, encountering an unfamiliar word in the middle of a chapter is common. With a physical book, your options are to grab your phone and look it up, which almost always leads to distraction, or skip it and lose a bit of meaning.

On a Kindle or most other e-readers, you tap the word and the definition appears instantly. You can translate it, add it to a vocabulary list, and get back to reading in seconds. I look up far more words now than I ever did with physical books, and my reading comprehension is genuinely better for it.

Taking notes you’ll actually use later

I used to annotate physical books with a pen, and those notes would just sit there on the page, never to be seen again. Transferring them somewhere useful took more effort than I was ever willing to put in.

With my Supernote Nomad, I can use its Digest feature to clip what I am reading and quickly add any additional handwritten notes. I can then export those notes to Obsidian and process them. 

If you use any e-reader, highlighting a passage and adding a note will take a couple of seconds. Most e-readers also aggregate all your highlights and notes in one place, allowing you to quickly riffle through your notes without flipping pages. 

With physical books, my notes died on the page. With an e-reader, they became something I actually use.

Since these are digital notes, you can process them into your note-taking app to further digest the material.

Books are cheaper and easier to buy

Buying physical books is always more expensive than getting the digital version. Also, since most publishers are phasing out mass-market paperbacks, we are left with trade paperback and hardcover options, which may look better but also cost significantly more.

E-books don’t have that problem. I have purchased several books at less than half the price I would have paid for a physical version. Also, most of the time, e-books are on sale, making them even more affordable. 

And when you find a book you want to read at midnight, you don’t have to wait for a delivery or drive to a store. You buy it and start reading immediately. The convenience is hard to overstate once you get used to it.

Should you switch?

If you love the experience of physical books, the covers, the smell, the shelf aesthetic, that’s a completely valid reason to stick with them. There’s nothing wrong with it. I myself am curating my own bookshelf, and there will always be a place for those special books. 

But for convenience and ease of discovery and reading, I recommend you at least invest in one e-reader. It’s also one of the best times to buy them, as you can get good options around $100

Since these are e-readers, you don’t even need to upgrade them as often as your phone. If you don’t accidentally break them, they can easily last 5-6 years, making them worth the investment.



Source link