Affected Systems
Everest Forms Pro WordPress plugin versions up to 1.9.12. Approximately 4,000 active installations at risk.
Exploitation Status
Active exploitation confirmed. Threat actors are exploiting CVE-2026-3300 in the wild.
Business Impact
Critical severity (CVSS 9.8) remote code execution vulnerability allows attackers to execute arbitrary code and achieve complete site compromise. Organizations running affected versions face immediate risk of full WordPress site takeover, data theft, malware injection, and potential lateral movement to backend infrastructure. Limited install base (4,000 sites) reduces overall exposure but does not diminish severity for affected organizations.
Urgency
🔴 Immediate
Recommended Actions
- Immediately identify all WordPress instances running Everest Forms Pro plugin versions up to 1.9.12 using asset inventory or vulnerability scanners
- Update Everest Forms Pro to version 1.9.13 or later if available, or disable/remove the plugin until patched version is confirmed
- Review WordPress access logs and web application firewall logs for suspicious POST requests or unusual file uploads targeting Everest Forms endpoints
- Conduct forensic review of affected WordPress sites for indicators of compromise including webshells, unauthorized admin accounts, and modified core files
- Implement web application firewall rules to block exploitation attempts if immediate patching is not feasible, and restrict WordPress admin access to trusted IP ranges
