CVE-2026-3300: Everest Forms Pro WordPress RCE Exploited — 29,300 Attack Attempts Blocked | CyberHawk Threat Intel

CVE-2026-3300 (CVSS 9.8) in Everest Forms Pro WordPress plugin is under active exploitation. Unauthenticated attackers inject PHP into eval() to create rogue admin accounts and deploy web shells.

2026-08-31T22:38:06.173Z
Rudra Verma, Senior Security Architect & Researcher