ctipilot.ch

Everest Forms Pro (WordPress) Calculation Addon unauthenticated eval() PHP code injection (CVSS 9.8); mass exploitation since 2026-04-13 creating rogue admin accounts; patched v1.9.13 (2026-03-18)

cve · CVE-2026-3300

Coverage timeline
2
first 2026-06-08 → last 2026-06-14
Peak priority
high
1 high · 1 notable
Sources cited
7
4 hosts
Sections touched
2
deep-dive, trending-vulnerabilities
Co-occurring entities
1
see Related entities below
ATT&CK techniques
4
pinned v19.1 · see below

ATT&CK techniques

4 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-06-08/cve-2026-3300-unauthenticated-eval-injection-in-a-commercial · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-06-08/cve-2026-3300-unauthenticated-eval-injection-in-a-commercial · ATT&CK page ↗

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-06-08/cve-2026-3300-unauthenticated-eval-injection-in-a-commercial · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-06-08/cve-2026-3300-unauthenticated-eval-injection-in-a-commercial · ATT&CK page ↗

T1136Create Account×1

Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.

Evidence: 2026-06-08/cve-2026-3300-unauthenticated-eval-injection-in-a-commercial · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-06-08/cve-2026-3300-unauthenticated-eval-injection-in-a-commercial · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-06-08/cve-2026-3300-unauthenticated-eval-injection-in-a-commercial · ATT&CK page ↗

Story timeline

  1. 2026-06-08CVE-2026-3300: unauthenticated eval() injection in a commercial WordPress plugin, and the patch-lag that turned a March fix into a June mass-exploitation campaign
    deep-diveCVE-2026-3300: unauthenticated eval() injection in a commercial WordPress plugin, and the patch-lag that turned a March fix into a June mass-exploitation
  2. 2026-06-08CVE-2026-3300 — Everest Forms Pro (WordPress): unauthenticated eval() injection, actively exploited at scale
    trending-vulnerabilities

Where this entity is cited

  • trending-vulnerabilities1
  • deep-dive1

Source distribution

  • attack.mitre.org4 (57%)
  • bleepingcomputer.com1 (14%)
  • thehackernews.com1 (14%)
  • wordfence.com1 (14%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Everest Forms Pro (WordPress) Calculation Addon unauthenticated eval() PHP code injection (CVSS 9.8); mass exploitation since 2026-04-13 creating rogue admin accounts; patched v1.9.13 (2026-03-18) (2)

2026-06-08 · view entry permalink →

NOTABLECVE-2026-3300exploited

CVE-2026-3300: unauthenticated eval() injection in a commercial WordPress plugin, and the patch-lag that turned a March fix into a June mass-exploitation campaign

Why this is the deep dive now. CVE-2026-3300 is a textbook web-app RCE that matters less for its novelty than for what it shows about patch lag in the commercial-plugin supply chain: the vendor fixed it on 18 March 2026, yet Wordfence has logged sustained mass exploitation from 13 April through at least 6 June, with a single-day peak of 17,900 blocked attempts on 16 May (Wordfence, 2026-06-06). WordPress underpins a large share of cantonal, municipal and agency web estates, so any public-sector site still running Everest Forms Pro ≤ 1.9.12 is exposed to a fully unauthenticated site takeover today — the patch existing for three months does not help a site that never applied it.

The bug. The vulnerability lives in the process_filter() function of the plugin's Calculation Addon, which builds a PHP expression string from user-submitted form-field values and evaluates it with eval() (BleepingComputer, 2026-06-06). The only input handling applied is sanitize_text_field(), which strips tags and normalises whitespace but does not escape single quotes or PHP syntax metacharacters. An unauthenticated attacker who submits a form containing a calculation field can therefore inject a single quote to terminate the intended string literal, append arbitrary PHP, and comment out the trailing remainder of the generated expression with //. Because the sink is eval(), this is direct code execution in the WordPress PHP context — no file write, no upload, no authentication. The CVE prerequisite is narrow but common: the form must include the Calculation Addon. Affected versions are ≤ 1.9.12; fixed in 1.9.13. The flaw was credited to researcher h0xilo (BleepingComputer, 2026-06-06).

Observed exploitation chain. The dominant in-the-wild payload uses the code-execution primitive to call WordPress's own wp_insert_user() and create a rogue account with the administrator role — converting a single unauthenticated POST into persistent privileged access to the site, from which attackers typically install webshells, SEO-spam injectors or redirect malware. Mapped to MITRE ATT&CK: initial access via T1190 Exploit Public-Facing Application; execution of injected PHP via T1059 Command and Scripting Interpreter; persistence by T1136 Create Account, after which the attacker operates with T1078 Valid Accounts.

Detection concepts (no IOCs). The highest-fidelity signal is unexpected administrator-account creation: hunt WordPress user_register events that assign the administrator role, and reconcile the live admin-user list against a known-good baseline — any account you cannot attribute to a person or process is suspect. At the request layer, alert on POSTs to the form-handling endpoints (admin-ajax.php and the plugin's AJAX actions) whose parameters contain PHP-syntax artefacts such as stray single quotes followed by function-call tokens or trailing // comment markers. Post-exploitation, watch for new or modified PHP files in wp-content/ and for outbound requests from the web host that correlate with webshell or SEO-spam behaviour. These are behavioural concepts, not signatures — tune to your own form traffic.

Hardening. Update Everest Forms Pro to 1.9.13 or later immediately; if you cannot patch on the spot, disable the Calculation Addon (the vulnerable code path) or take affected forms offline, and audit for already-created rogue admin accounts before re-enabling. A WAF rule blocking PHP-metacharacter patterns in form-submission parameters is a reasonable compensating control, but it is mitigation, not a fix. More broadly, this CVE is an argument for maintaining an inventory of commercial plugins and their versions across your WordPress estate and wiring plugin-update monitoring into change management — the recurring failure mode here is not the vulnerability class but the months-long gap between a vendor fix and its deployment.

Why this is the deep dive now.

ctipilot v2 brief (migrated)
vulnerability08 Jun 05:00Zmulti-sourceOpen finding ↗

2026-06-08 · view entry permalink →

HIGHCVE-2026-3300exploited

CVE-2026-3300 — Everest Forms Pro (WordPress): unauthenticated eval() injection, actively exploited at scale

A pre-authentication PHP code-injection (CVSS 9.8) in the Calculation Addon of the Everest Forms Pro plugin lets an unauthenticated visitor break out of a calculated form field and execute attacker-controlled PHP, the observed payload being creation of a rogue administrator account (Wordfence, 2026-06-06; BleepingComputer, 2026-06-06). The vendor patched it in v1.9.13 on 18 March 2026, but Wordfence telemetry shows mass exploitation running since 13 April (29,300+ blocked attempts, a single-day spike of 17,900 on 16 May, still active as of 6 June). Inclusion gate: vendor-confirmed in-the-wild exploitation at scale. Full mechanics, detection and hardening in § 5.

A pre-authentication PHP code-injection (CVSS 9.8) in the Calculation Addon of the Everest Forms Pro plugin lets an unauthenticated visitor break out of a calculated form field and execute attacker-controlled PHP, the observed payload being creation of a rogue administrator account (Wordfence …

ctipilot v2 brief (migrated)
vulnerability08 Jun 05:00Zmulti-sourceOpen finding ↗