Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site compromise.
The vulnerability in question is CVE-2026-3300 (CVSS score: 9.8), a remote code execution bug impacting all versions of the plugin up to, and including, 1.9.12. A patch fo...
Get updates from The Hacker News | #1 Trusted Source for Cybersecurity News via email, on your phone or read them on follow.it on your own custom news page.
You can filter the news from The Hacker News | #1 Trusted Source for Cybersecurity News that get delivered to you using tags or topics or you can opt for all of them. Unsubscription is also very simple.
See the latest news from The Hacker News | #1 Trusted Source for Cybersecurity News below.
Site title: The Hacker News | #1 Trusted Source for Cybersecurity News