Attackers are actively exploiting CVE-2026-3300, a critical unauthenticated remote code execution flaw in the Everest Forms Pro WordPress plugin, to fully compromise vulnerable sites. The bug affects versions through 1.9.12 and was fixed in 1.9.13. It stems from the plugin’s Complex Calculation feature, where user-controlled input in process_filter() is concatenated into PHP code and executed with eval(), allowing arbitrary PHP injection through crafted form submissions, often via the /wp-admin/admin-ajax.php endpoint.
Wordfence reported exploitation beginning on April 13 and escalating into mass attacks, with more than 29,300 exploit attempts blocked overall and over 17,900 on May 16 alone. A recurring payload creates a rogue administrator account named diksimarina, giving attackers persistent access to upload webshells, install backdoors, alter site content, and potentially pivot deeper into the hosting environment. Defenders are being urged to upgrade immediately to 1.9.13 or later, audit WordPress administrator accounts for unauthorized users, and review logs for suspicious requests and known malicious IP activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Telemetry showed a major surge in exploitation on May 16, 2026, with more than 17,900 exploit requests blocked that day alone. Reports said attackers were often using payloads to create a WordPress administrator account named "diksimarina."
Wordfence observed exploitation activity targeting CVE-2026-3300 beginning on April 13, 2026. The attacks targeted unpatched WordPress sites and commonly attempted to create rogue administrator accounts for persistence.
The Everest Forms Pro remote code execution vulnerability was publicly disclosed after the patch release. Reporting described the flaw as critical, with a CVSS score of 9.8, and tied it to improper input handling in the plugin's calculation functionality.
A fix for the critical unauthenticated remote code execution flaw CVE-2026-3300 in Everest Forms Pro was released in version 1.9.13. The vulnerability affected versions up to 1.9.12 and involved unsafe use of eval() in the Complex Calculation feature.
Sansec described the GorgonAgora operation as active since August 2025, using 5,714 fake .shop storefronts impersonating major brands to steal payment card data. The campaign reportedly used a fake Stripe iframe and infrastructure tied to a server in Moldova to relay 3D Secure challenges and evade detection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.