Affected Systems

Everest Forms Pro plugin for WordPress. Specific affected versions not disclosed. All WordPress sites running this premium plugin are potentially at risk.

Exploitation Status

Active exploitation confirmed. Attackers are leveraging CVE-2026-3300 in the wild to achieve full site compromise.

Business Impact

Complete site takeover enables attackers to inject malware, steal credentials, deface content, pivot to backend systems, or use compromised sites for phishing/malware distribution. Organizations using Everest Forms Pro face immediate risk of data breach and reputational damage. CVSS score not yet published.

Urgency

🔴 Immediate

Recommended Actions

  • Immediately identify all WordPress instances running Everest Forms Pro plugin via asset inventory or wp-cli scan
  • Disable or uninstall Everest Forms Pro plugin until vendor releases patched version
  • Review WordPress admin accounts, file integrity, and recent plugin/theme changes for indicators of compromise
  • Monitor web server logs for unusual POST requests to /wp-admin/admin-ajax.php or plugin endpoints
  • Apply vendor security update immediately when available and verify plugin version post-patch