Skip to content
Photonews Logo Photonews logo
  • Home
  • Pakistan
    • Punjab
    • Sindh
    • Khyber Pakhtunkhwa
    • Azad Jammu Kashmir
    • Balochistan
    • Gilgit – Baltistan
  • World
  • Business
  • Entertainment
  • Videos
    Fire Point co-owner Denys Shtilerman speaks during an interview with journalist Alesia Batsman.
    Videos

    Ukraine Nuclear Weapons Claim Made By Fire Point Co-Owner

    June 5, 2026 2 Min Read
    Emilia Clarke Game Of Thrones with interview Variety
    EntertainmentVideos

    Emilia Clarke Denies $300,000 Game Of Thrones Pay Claim

    May 30, 2026 1 Min Read
    Shakira Dai Dai's Song For World Cup 2026
    Videos

    Shakira Dai Dai Song Released For World Cup 2026

    May 24, 2026 2 Min Read
  • Sports
  • Technology
  • Offbeat
  • Blog
  • Contact
Reading: Everest Forms Pro Flaw Lets Attackers Hijack Sites
PhotoNews PakistanPhotoNews Pakistan
Font ResizerAa
Search
  • Home
  • Pakistan
    • Punjab
    • Sindh
    • Khyber Pakhtunkhwa
    • Balochistan
    • Azad Jammu Kashmir
    • Gilgit – Baltistan
  • World
  • Business
  • Entertainment
  • Videos
  • Sports
  • Technology
  • Offbeat
  • Blog
  • Contact
Have an existing account? Sign In
Follow US
© 2022 Photonews. All Rights Reserved.
WordPress logo connected to cybersecurity scan panels showing backdoor detected and backdoor installed alerts.
PhotoNews Pakistan > Tech > Everest Forms Pro Flaw Lets Attackers Hijack Sites
Tech

Everest Forms Pro Flaw Lets Attackers Hijack Sites

Web Desk
By Web Desk Published June 7, 2026 2 Min Read
Share
graphic shows a WordPress security scan detecting possible backdoor threats and suspicious files.
SHARE

Attackers are exploiting a flaw in Everest Forms Pro for WordPress to execute PHP code and create rogue administrator accounts, Wordfence said.

The vulnerability, tracked as CVE-2026-3300, carries a CVSS score of 9.8 and affects Everest Forms Pro versions up to and including 1.9.12. Wordfence said WPEverest patched the bug in version 1.9.13 on March 18, 2026.

Wordfence said the remote code execution bug sits in the plugin’s Complex Calculation feature. The Calculation Addon’s process_filter() function placed user-submitted field values into a PHP code string without proper escaping before sending it to eval().

That flaw allows unauthenticated attackers to submit crafted values via string-type form fields when a site uses Complex Calculation. Successful exploitation can allow arbitrary PHP execution on the server, according to Wordfence.

Read: Anthropic Launches Project Glasswing to Fight AI Cyber Threats

Wordfence said attackers have used the bug to create administrator accounts, deploy web shells and deepen access inside compromised WordPress environments. The company said it observed active exploitation starting April 13, 2026.

The most common payload tries to create an administrator account named “diksimarina” using the email address “diksimarina@gmail.com,” according to the source material and Wordfence data. Site owners should remove any unauthorised accounts and inspect logs for suspicious requests.

WPEverest users should update Everest Forms Pro to version 1.9.13 or later. Administrators should also review plugin files, check recent file changes and look for web shells after patching.

TAGGED:Featured
Share This Article
Facebook Twitter Pinterest Whatsapp Whatsapp LinkedIn Email Copy Link Print
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Advertisement

Recent Posts

WordPress logo connected to cybersecurity scan panels showing backdoor detected and backdoor installed alerts.

Everest Forms Pro Flaw Lets Attackers Hijack Sites

A large crowd of Muslim worshippers surrounds the Holy Kaaba inside Masjid al-Haram in Makkah.

Pakistan Hajj Award Won Again After 2026 Operations

JAAC banned in AJK under Azad Jammu and Kashmir Anti-Terrorism Act 2014

JAAC Proscribed Organisation Ahead Of AJK Strike

Post Archives

More Popular from Photonews

A damaged airport interior shows collapsed roof sections, debris, water on the floor, and an escalator after a reported Iranian missile attack.
World

Kuwait Airport Strike Kills One, Injures 63

1 Min Read
Anmol Pinky case inquiry leads CTD to recommend dismissal of two police officers.
Sindh

Anmol Pinky Case: CTD Seeks Dismissal of Two Officers

1 Min Read
President Donald Trump stands with Todd Blanche, then deputy attorney general, during a 2025 news briefing.
World

Todd Blanche Attorney General Nomination Announced by Trump

2 Min Read
Azad Jammu Kashmir

AJK Mobile Internet Suspension Ordered Before June 9 Strike

Authorities have ordered a suspension of mobile internet in AJK from 11:30 pm. This comes ahead…

June 6, 2026
Business

KSE-100 Index Rises 421 Points At Pakistan Stock Exchange

The KSE-100 Index rose 421.57 points, or 0.25%, to close at 171,021.77 at the Pakistan Stock…

June 2, 2026
Tech

Lockheed Drone Weapon Destroys Shahed-Type Target

Lockheed Martin has destroyed a Shahed-type attack drone target using a Lockheed drone weapon system during…

June 5, 2026
Sindh

Karachi Weather Today: PMD Rules Out Rainfall

Karachi weather today will remain hot and humid, with the Met Office ruling out any chance…

June 3, 2026
PhotoNews Pakistan

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

    Categories

    • World
    • Pakistan
    • Punjab
    • Sindh
    • Khyber Pakhtunkhwa
    • Balochistan
    • Azad Jammu Kashmir

     

    • Top News
    • Business
    • Entertainment
    • Sports
    • Videos
    • Tech
    • Offbeat
    • Blog
    • About Us
    • Privacy Policy
    • Code of Ethics & Editorial Standards

    © 2026 Phototnews
    All Rights Reserved.

    Welcome Back!

    Sign in to your account

    Lost your password?