# Everest Forms Pro WordPress Plugin CVE-2026-3300 — Unauthenticated RCE via Calculation Addon process_filter() eval() Injection (CVSS 9.8, Active Exploitation)

> Critical unauthenticated remote code execution in Everest Forms Pro (<= 1.9.12). The Calculation Addon's process_filter() concatenates user-submitted form field values into a PHP expression and passes it to eval(); sanitize_text_field() does not escape single quotes, allowing PHP injection via any string-type field (text/email/url/select/radio) on forms with the Complex Calculation feature enabled. Patched in 1.9.13 (2026-03-18), disclosed 2026-06-05, active exploitation from 2026-04-13 with 29,300+ Wordfence-blocked attempts (17,900+ on 2026-05-16). Attackers register rogue admin accounts ('diksimarina') and drop webshells.

- **Published:** 2026-06-06T00:00:00Z
- **Last reviewed:** 2026-06-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0689
- **ID:** TL-2026-0689
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 13 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-3300

## Description

CVE-2026-3300 is a critical (CVSS 9.8) unauthenticated remote code execution vulnerability in the Everest Forms Pro WordPress plugin by WPEverest, affecting all versions up to and including 1.9.12 (~4,000 active installations).

ROOT CAUSE: The vulnerability resides in the plugin's Calculation Addon. When a form has the 'Complex Calculation' feature enabled, the addon's process_filter() function builds a PHP expression string by directly concatenating user-submitted form field values, then passes that string to PHP's eval() for dynamic evaluation. Input is passed through sanitize_text_field(), but that WordPress helper only strips tags and normalizes whitespace for database/display contexts — it does NOT escape single quotes or other PHP string-context metacharacters. An attacker can therefore submit a value containing a single quote to terminate the wrapping PHP string literal and append arbitrary PHP code.

EXPLOIT CHAIN: (1) Initial Access / Execution — the attacker sends an unauthenticated POST to /wp-admin/admin-ajax.php with action=everest_forms_submit, supplying a crafted value in any string-type field (text, email, URL, select, radio). A representative payload is `'); phpinfo(); //` which closes the string and statement, injects a PHP call, and comments out the trailing original code. Because eval() runs in the PHP-FPM/web-server worker context, the injected code executes with the privileges of the web server user. (2) Persistence / Privilege Escalation — observed payloads use wp_insert_user()/wp_create_user() semantics to register a rogue WordPress administrator account named 'diksimarina' (diksimarina@gmail.com), granting durable authenticated admin access independent of the original eval() primitive. (3) Persistence — attackers write PHP webshells to the webroot for ongoing command execution. (4) Command and Control — webshells and rogue-admin sessions provide hands-on-keyboard access for follow-on actions.

IN-THE-WILD ACTIVITY: WPEverest released the fix in 1.9.13 on 2026-03-18; public disclosure followed on 2026-06-05 (GitHub Advisory GHSA-jfqc-5rvh-wp99, 2026-03-30). Mass exploitation began 2026-04-13. Wordfence has blocked over 29,300 exploit attempts, including a single-day peak of 17,900+ on 2026-05-16; a single source IP (202.56.2.126) accounts for 26,300+ of the blocked attempts. A public proof-of-concept is available.

The vulnerability is opportunistic and mass-scanned rather than targeted; any internet-facing WordPress site running Everest Forms Pro <= 1.9.12 with a Complex Calculation form is exploitable without authentication.

## MITRE ATT&CK

- T1595 Active Scanning
- T1595.002 Vulnerability Scanning
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1059.011 Lua
- T1505.003 Server Software Component: Web Shell
- T1136.001 Create Account: Local Account
- T1078 Valid Accounts
- T1070 Indicator Removal
- T1105 Ingress Tool Transfer

## Sources

- [Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites](https://thehackernews.com/2026/06/hackers-exploit-critical-everest-forms.html)
- [GitHub Advisory GHSA-jfqc-5rvh-wp99 (CVE-2026-3300)](https://github.com/advisories/GHSA-jfqc-5rvh-wp99)
- [CVE-2026-3300: Everest Forms Pro WordPress RCE Vulnerability](https://www.sentinelone.com/vulnerability-database/cve-2026-3300/)
- [Everest Forms Pro Vulnerability Allows Remote Code Execution](https://www.infosecurity-magazine.com/news/everest-forms-pro-rce-actively/)
- [CVE-2026-3300 everest-forms-pro Proof of Concept](https://atomicedge.io/cve-proof/cve-2026-3300-everest-forms-pro-version-1-9-12-critical-vulnerability-proof-of-concept/)
- [Hackers Actively Exploiting WordPress Plugin Vulnerability to Inject Malicious PHP Code](https://cybersecuritynews.com/wordpress-plugin-vulnerability-exploit/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0689
