---
schema: 1
kind: vulnerability
title: "CVE-2026-3300 — Everest Forms Pro (WordPress): unauthenticated eval() injection, actively exploited at scale"
headline: "CVE-2026-3300 — Everest Forms Pro (WordPress): unauthenticated eval() injection, actively exploited at scale"
summary: "Everest Forms Pro (WordPress) CVE-2026-3300 — unauthenticated eval() injection under mass exploitation. A pre-auth PHP code-injection in the plugin's Calculation Addon lets attackers create rogue administrator accounts; Wordfence has blocked 29,300+ attempts since 13 April despite a fix shipping 18 March (Wordfence, 2026-06-06). Patch lag, not the bug, is the story — full technical analysis in § 5."
discovered_at: "2026-06-08T05:00:02Z"
event_date: 2026-06-06
run_id: 2026-06-08-1a0ce644
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - rce
  - pre-auth
regions:
  - global
sectors:
  - public-sector
entities: []
cves:
  - id: CVE-2026-3300
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - patch-available
sources:
  - url: "https://www.wordfence.com/blog/2026/06/attackers-actively-exploiting-critical-vulnerability-in-everest-forms-pro-plugin/"
    publisher: Wordfence
    role: primary
  - url: "https://www.bleepingcomputer.com/news/security/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites/"
    publisher: BleepingComputer
    role: corroborating
  - url: "https://thehackernews.com/2026/06/hackers-exploit-critical-everest-forms.html"
    publisher: "The Hacker News, 2026-06-05"
    role: corroborating
closed_sources: []
evidence:
  - quote: "A pre-authentication PHP code-injection (CVSS 9.8) in the Calculation Addon of the Everest Forms Pro plugin lets an unauthenticated visitor break out of a calculated form field and execute attacker-controlled PHP, the observed payload being creation of a rogue administrator account (Wordfence …"
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-08.md
---

A pre-authentication PHP code-injection (CVSS 9.8) in the Calculation Addon of the Everest Forms Pro plugin lets an unauthenticated visitor break out of a calculated form field and execute attacker-controlled PHP, the observed payload being creation of a rogue administrator account ([Wordfence, 2026-06-06](https://www.wordfence.com/blog/2026/06/attackers-actively-exploiting-critical-vulnerability-in-everest-forms-pro-plugin/); [BleepingComputer, 2026-06-06](https://www.bleepingcomputer.com/news/security/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites/)). The vendor patched it in **v1.9.13 on 18 March 2026**, but Wordfence telemetry shows mass exploitation running since 13 April (29,300+ blocked attempts, a single-day spike of 17,900 on 16 May, still active as of 6 June). Inclusion gate: vendor-confirmed in-the-wild exploitation at scale. **Full mechanics, detection and hardening in § 5.**
