Threat reportVulnerabilityTL-2026-0689
Everest Forms Pro WordPress Plugin CVE-2026-3300 — Unauthenticated RCE via Calculation Addon process_filter() eval() Injection (CVSS 9.8, Active Exploitation)
Everest Forms Pro WordPress Plugin CVE-2026-3300 (TL-2026-0689) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-06-06. It has no confirmed attribution, affects WPEverest Everest Forms Pro, references 1 CVE (CVE-2026-3300), maps to 10 MITRE ATT&CK techniques (T1059, T1059.011, T1070), and is covered by 9 detection rules and 13 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 10MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 13Indicators of compromise
Key facts for TL-2026-0689
- Threat ID
- TL-2026-0689
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- technology, small-business, e-commerce, media, education, nonprofit
- Target regions
- Global, North America, Europe, Asia
- Detection rules
- 9
- Indicators of compromise
- 13
How Everest Forms Pro WordPress Plugin CVE-2026-3300 works
Critical unauthenticated remote code execution in Everest Forms Pro (<= 1.9.12). The Calculation Addon's process_filter() concatenates user-submitted form field values into a PHP expression and passes it to eval(); sanitize_text_field() does not escape single quotes, allowing PHP injection via any string-type field (text/email/url/select/radio) on forms with the Complex Calculation feature enabled. Patched in 1.9.13 (2026-03-18), disclosed 2026-06-05, active exploitation from 2026-04-13 with 29,300+ Wordfence-blocked attempts (17,900+ on 2026-05-16). Attackers register rogue admin accounts ('diksimarina') and drop webshells.
CVE-2026-3300 is a critical (CVSS 9.8) unauthenticated remote code execution vulnerability in the Everest Forms Pro WordPress plugin by WPEverest, affecting all versions up to and including 1.9.12 (~4,000 active installations).
ROOT CAUSE: The vulnerability resides in the plugin's Calculation Addon. When a form has the 'Complex Calculation' feature enabled, the addon's process_filter() function builds a PHP expression string by directly concatenating user-submitted form field values, then passes that string to PHP's eval() for dynamic evaluation. Input is passed through sanitize_text_field(), but that WordPress helper only strips tags and normalizes whitespace for database/display contexts — it does NOT escape single quotes or other PHP string-context metacharacters. An attacker can therefore submit a value containing a single quote to terminate the wrapping PHP string literal and append arbitrary PHP code.
EXPLOIT CHAIN: (1) Initial Access / Execution — the attacker sends an unauthenticated POST to /wp-admin/admin-ajax.php with action=everest_forms_submit, supplying a crafted value in any string-type field (text, email, URL, select, radio). A representative payload is `'); phpinfo(); //` which closes the string and statement, injects a PHP call, and comments out the trailing original code. Because eval() runs in the PHP-FPM/web-server worker context, the injected code executes with the privileges of the web server user. (2) Persistence / Privilege Escalation — observed payloads use wp_insert_user()/wp_create_user() semantics to register a rogue WordPress administrator account named 'diksimarina' (diksimarina@gmail.com), granting durable authenticated admin access independent of the original eval() primitive. (3) Persistence — attackers write PHP webshells to the webroot for ongoing command execution. (4) Command and Control — webshells and rogue-admin sessions provide hands-on-keyboard access for follow-on actions.
IN-THE-WILD ACTIVITY: WPEverest released the fix in 1.9.13 on 2026-03-18; public disclosure followed on 2026-06-05 (GitHub Advisory GHSA-jfqc-5rvh-wp99, 2026-03-30). Mass exploitation began 2026-04-13. Wordfence has blocked over 29,300 exploit attempts, including a single-day peak of 17,900+ on 2026-05-16; a single source IP (202.56.2.126) accounts for 26,300+ of the blocked attempts. A public proof-of-concept is available.
The vulnerability is opportunistic and mass-scanned rather than targeted; any internet-facing WordPress site running Everest Forms Pro <= 1.9.12 with a Complex Calculation form is exploitable without authentication.
MITRE ATT&CK techniques used in TL-2026-0689
Execution
T1059 Command and Scripting Interpreter; T1059.011 Lua
Defense Evasion
Privilege Escalation
Command and Control
Persistence
T1136.001 Create Account: Local Account; T1505.003 Server Software Component: Web Shell
Initial Access
T1190 Exploit Public-Facing Application
Reconnaissance
Affected products and versions in Everest Forms Pro WordPress Plugin CVE-2026-3300
- WPEverest — Everest Forms Pro
Vulnerable versions: <= 1.9.12
Fixed in: 1.9.13
Remediation for Everest Forms Pro WordPress Plugin CVE-2026-3300
Patches
- Everest Forms Pro 1.9.13 (released 2026-03-18) — fixes process_filter() input handling
Immediate actions
- Update Everest Forms Pro to 1.9.13 or later immediately
- Audit wp_users for unauthorized administrator accounts, especially 'diksimarina' (diksimarina@gmail.com), and remove them
- Block the known exploitation source IPs at the perimeter/WAF (202.56.2.126, 209.146.60.26, 15.235.166.18, 185.78.165.153, 2402:1f00:8000:800::40db)
- Hunt the webroot for recently added/modified PHP files and webshells
Workarounds
- Disable the Calculation Addon, or remove the 'Complex Calculation' feature from all live forms until patched
- Take affected forms offline if patching cannot be performed immediately
Longer-term hardening
- Deploy a WAF (e.g. Wordfence) with virtual patching for CVE-2026-3300
- Run PHP-FPM with a least-privilege user and disable dangerous functions (eval is not disableable, but disable system/exec/passthru/proc_open via disable_functions)
- Implement file integrity monitoring on the WordPress webroot
- Enforce 2FA on all administrator accounts and alert on new admin creation
CVEs associated with Everest Forms Pro WordPress Plugin CVE-2026-3300
CVE-2026-3300
Weaknesses (CWE) in Everest Forms Pro WordPress Plugin CVE-2026-3300
Timeline of Everest Forms Pro WordPress Plugin CVE-2026-3300
- WPEverest releases Everest Forms Pro 1.9.13 fixing the process_filter() eval() injection.
- GitHub Advisory GHSA-jfqc-5rvh-wp99 assigned for CVE-2026-3300.
- Mass in-the-wild exploitation begins; Wordfence starts blocking attempts.
- Single-day peak of 17,900+ blocked exploit attempts observed by Wordfence.
- Public disclosure of active exploitation by The Hacker News and other outlets.
- Threadlinqs Intelligence publishes TL-2026-0689; 29,300+ total attempts blocked, ~4,000 sites remain exposed.
Sources cited for Everest Forms Pro WordPress Plugin CVE-2026-3300
- Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites
- GitHub Advisory GHSA-jfqc-5rvh-wp99 (CVE-2026-3300)
- CVE-2026-3300: Everest Forms Pro WordPress RCE Vulnerability
- Everest Forms Pro Vulnerability Allows Remote Code Execution
- CVE-2026-3300 everest-forms-pro Proof of Concept
- Hackers Actively Exploiting WordPress Plugin Vulnerability to Inject Malicious PHP Code
Detection coverage for TL-2026-0689
As of 2026-06-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0689 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.