Threat reportVulnerabilityTL-2026-0689

Everest Forms Pro WordPress Plugin CVE-2026-3300 — Unauthenticated RCE via Calculation Addon process_filter() eval() Injection (CVSS 9.8, Active Exploitation)

criticalACTIVE

Everest Forms Pro WordPress Plugin CVE-2026-3300 (TL-2026-0689) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-06-06. It has no confirmed attribution, affects WPEverest Everest Forms Pro, references 1 CVE (CVE-2026-3300), maps to 10 MITRE ATT&CK techniques (T1059, T1059.011, T1070), and is covered by 9 detection rules and 13 indicators of compromise.

CVSS
9.8/10Critical
CVEs
1Referenced vulnerabilities
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
13Indicators of compromise

Key facts for TL-2026-0689

Threat ID
TL-2026-0689
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
technology, small-business, e-commerce, media, education, nonprofit
Target regions
Global, North America, Europe, Asia
Detection rules
9
Indicators of compromise
13

How Everest Forms Pro WordPress Plugin CVE-2026-3300 works

Critical unauthenticated remote code execution in Everest Forms Pro (<= 1.9.12). The Calculation Addon's process_filter() concatenates user-submitted form field values into a PHP expression and passes it to eval(); sanitize_text_field() does not escape single quotes, allowing PHP injection via any string-type field (text/email/url/select/radio) on forms with the Complex Calculation feature enabled. Patched in 1.9.13 (2026-03-18), disclosed 2026-06-05, active exploitation from 2026-04-13 with 29,300+ Wordfence-blocked attempts (17,900+ on 2026-05-16). Attackers register rogue admin accounts ('diksimarina') and drop webshells.

CVE-2026-3300 is a critical (CVSS 9.8) unauthenticated remote code execution vulnerability in the Everest Forms Pro WordPress plugin by WPEverest, affecting all versions up to and including 1.9.12 (~4,000 active installations).

ROOT CAUSE: The vulnerability resides in the plugin's Calculation Addon. When a form has the 'Complex Calculation' feature enabled, the addon's process_filter() function builds a PHP expression string by directly concatenating user-submitted form field values, then passes that string to PHP's eval() for dynamic evaluation. Input is passed through sanitize_text_field(), but that WordPress helper only strips tags and normalizes whitespace for database/display contexts — it does NOT escape single quotes or other PHP string-context metacharacters. An attacker can therefore submit a value containing a single quote to terminate the wrapping PHP string literal and append arbitrary PHP code.

EXPLOIT CHAIN: (1) Initial Access / Execution — the attacker sends an unauthenticated POST to /wp-admin/admin-ajax.php with action=everest_forms_submit, supplying a crafted value in any string-type field (text, email, URL, select, radio). A representative payload is `'); phpinfo(); //` which closes the string and statement, injects a PHP call, and comments out the trailing original code. Because eval() runs in the PHP-FPM/web-server worker context, the injected code executes with the privileges of the web server user. (2) Persistence / Privilege Escalation — observed payloads use wp_insert_user()/wp_create_user() semantics to register a rogue WordPress administrator account named 'diksimarina' (diksimarina@gmail.com), granting durable authenticated admin access independent of the original eval() primitive. (3) Persistence — attackers write PHP webshells to the webroot for ongoing command execution. (4) Command and Control — webshells and rogue-admin sessions provide hands-on-keyboard access for follow-on actions.

IN-THE-WILD ACTIVITY: WPEverest released the fix in 1.9.13 on 2026-03-18; public disclosure followed on 2026-06-05 (GitHub Advisory GHSA-jfqc-5rvh-wp99, 2026-03-30). Mass exploitation began 2026-04-13. Wordfence has blocked over 29,300 exploit attempts, including a single-day peak of 17,900+ on 2026-05-16; a single source IP (202.56.2.126) accounts for 26,300+ of the blocked attempts. A public proof-of-concept is available.

The vulnerability is opportunistic and mass-scanned rather than targeted; any internet-facing WordPress site running Everest Forms Pro <= 1.9.12 with a Complex Calculation form is exploitable without authentication.

MITRE ATT&CK techniques used in TL-2026-0689

Execution

T1059 Command and Scripting Interpreter; T1059.011 Lua

Defense Evasion

T1070 Indicator Removal

Privilege Escalation

T1078 Valid Accounts

Command and Control

T1105 Ingress Tool Transfer

Persistence

T1136.001 Create Account: Local Account; T1505.003 Server Software Component: Web Shell

Initial Access

T1190 Exploit Public-Facing Application

Reconnaissance

T1595 Active Scanning; T1595.002 Vulnerability Scanning

Affected products and versions in Everest Forms Pro WordPress Plugin CVE-2026-3300

  • WPEverest — Everest Forms Pro
    Vulnerable versions: <= 1.9.12
    Fixed in: 1.9.13

Remediation for Everest Forms Pro WordPress Plugin CVE-2026-3300

Patches

  • Everest Forms Pro 1.9.13 (released 2026-03-18) — fixes process_filter() input handling

Immediate actions

  • Update Everest Forms Pro to 1.9.13 or later immediately
  • Audit wp_users for unauthorized administrator accounts, especially 'diksimarina' (diksimarina@gmail.com), and remove them
  • Block the known exploitation source IPs at the perimeter/WAF (202.56.2.126, 209.146.60.26, 15.235.166.18, 185.78.165.153, 2402:1f00:8000:800::40db)
  • Hunt the webroot for recently added/modified PHP files and webshells

Workarounds

  • Disable the Calculation Addon, or remove the 'Complex Calculation' feature from all live forms until patched
  • Take affected forms offline if patching cannot be performed immediately

Longer-term hardening

  • Deploy a WAF (e.g. Wordfence) with virtual patching for CVE-2026-3300
  • Run PHP-FPM with a least-privilege user and disable dangerous functions (eval is not disableable, but disable system/exec/passthru/proc_open via disable_functions)
  • Implement file integrity monitoring on the WordPress webroot
  • Enforce 2FA on all administrator accounts and alert on new admin creation

CVEs associated with Everest Forms Pro WordPress Plugin CVE-2026-3300

CVE-2026-3300

Weaknesses (CWE) in Everest Forms Pro WordPress Plugin CVE-2026-3300

CWE-94, CWE-95, CWE-20, CWE-116

Timeline of Everest Forms Pro WordPress Plugin CVE-2026-3300

  • WPEverest releases Everest Forms Pro 1.9.13 fixing the process_filter() eval() injection.
  • GitHub Advisory GHSA-jfqc-5rvh-wp99 assigned for CVE-2026-3300.
  • Mass in-the-wild exploitation begins; Wordfence starts blocking attempts.
  • Single-day peak of 17,900+ blocked exploit attempts observed by Wordfence.
  • Public disclosure of active exploitation by The Hacker News and other outlets.
  • Threadlinqs Intelligence publishes TL-2026-0689; 29,300+ total attempts blocked, ~4,000 sites remain exposed.

Sources cited for Everest Forms Pro WordPress Plugin CVE-2026-3300

Detection coverage for TL-2026-0689

As of 2026-06-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0689 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
13 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats