Skip to content
Photonews Logo Photonews logo
  • Home
  • Pakistan
    • Punjab
    • Sindh
    • Khyber Pakhtunkhwa
    • Azad Jammu Kashmir
    • Balochistan
    • Gilgit – Baltistan
  • World
  • Business
  • Entertainment
  • Videos
    Olivia Wilde Trailer Gregg Araki Thriller I Want Your Sex Trailer Shows Olivia
    Videos

    Olivia Wilde Trailer Shows Gregg Araki Thriller I Want Your Sex Trailer Shows Olivia

    June 11, 2026 1 Min Read
    Alia Bhatt Alpha teaser shows the actor entering action mode in YRF’s female-led spy thriller.
    Videos

    Alia Bhatt Alpha Teaser Shows Bobby Deol Training Her

    June 10, 2026 1 Min Read
    Fire Point co-owner Denys Shtilerman speaks during an interview with journalist Alesia Batsman.
    Videos

    Ukraine Nuclear Weapons Claim Made By Fire Point Co-Owner

    June 5, 2026 2 Min Read
  • Sports
  • Technology
  • Offbeat
  • Blog
  • Contact
Reading: Everest Forms Pro Flaw Lets Attackers Hijack Sites
PhotoNews PakistanPhotoNews Pakistan
Font ResizerAa
Search
  • Home
  • Pakistan
    • Punjab
    • Sindh
    • Khyber Pakhtunkhwa
    • Balochistan
    • Azad Jammu Kashmir
    • Gilgit – Baltistan
  • World
  • Business
  • Entertainment
  • Videos
  • Sports
  • Technology
  • Offbeat
  • Blog
  • Contact
Have an existing account? Sign In
Follow US
© 2022 Photonews. All Rights Reserved.
WordPress logo connected to cybersecurity scan panels showing backdoor detected and backdoor installed alerts.
PhotoNews Pakistan > Tech > Everest Forms Pro Flaw Lets Attackers Hijack Sites
Tech

Everest Forms Pro Flaw Lets Attackers Hijack Sites

Web Desk
By Web Desk Published June 7, 2026 2 Min Read
Share
graphic shows a WordPress security scan detecting possible backdoor threats and suspicious files.
SHARE

Attackers are exploiting a flaw in Everest Forms Pro for WordPress to execute PHP code and create rogue administrator accounts, Wordfence said.

The vulnerability, tracked as CVE-2026-3300, carries a CVSS score of 9.8 and affects Everest Forms Pro versions up to and including 1.9.12. Wordfence said WPEverest patched the bug in version 1.9.13 on March 18, 2026.

Wordfence said the remote code execution bug sits in the plugin’s Complex Calculation feature. The Calculation Addon’s process_filter() function placed user-submitted field values into a PHP code string without proper escaping before sending it to eval().

That flaw allows unauthenticated attackers to submit crafted values via string-type form fields when a site uses Complex Calculation. Successful exploitation can allow arbitrary PHP execution on the server, according to Wordfence.

Read: Anthropic Launches Project Glasswing to Fight AI Cyber Threats

Wordfence said attackers have used the bug to create administrator accounts, deploy web shells and deepen access inside compromised WordPress environments. The company said it observed active exploitation starting April 13, 2026.

The most common payload tries to create an administrator account named “diksimarina” using the email address “diksimarina@gmail.com,” according to the source material and Wordfence data. Site owners should remove any unauthorised accounts and inspect logs for suspicious requests.

WPEverest users should update Everest Forms Pro to version 1.9.13 or later. Administrators should also review plugin files, check recent file changes and look for web shells after patching.

TAGGED:Featured
Share This Article
Facebook Twitter Pinterest Whatsapp Whatsapp LinkedIn Email Copy Link Print
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Advertisement

Recent Posts

Kohlu earthquake shakes Balochistan after earlier tremors damaged houses in Kingri.

Kohlu Earthquake: 4.3 Tremor Hits After 70 Houses Damaged

Woman carrying a child near collapsed buildings after Venezuela earthquakes killed at least 920 people and injured 3,360.

Venezuela Earthquakes Kill 920 as Rescuers Search La Guaira

Petrol diesel prices unchanged in Pakistan as kerosene oil price is cut by Rs6.85 per litre

Petrol Diesel Prices Unchanged, Kerosene Cut Rs6.85

Post Archives

More Popular from Photonews

Israel Lebanon talks resume in Washington as the US seeks to reinforce Lebanon’s fragile ceasefire and push a security agreement.
World

Israel, Lebanon Resume US-mediated Talks in Washington

1 Min Read
US stock futures fell as AI valuation worries, an Asia chip selloff and OpenAI IPO delay concerns weighed on technology shares.
Business

US Stock Futures Fall as AI Worries Hit Tech Rally

2 Min Read
Pezeshkian Pakistan visit is set for Tuesday as Iran’s president meets top leaders for bilateral and regional talks.
Pakistan

FO Confirms Iranian President Pezeshkian’s Visit to Pakistan on Tuesday

2 Min Read
World

UN Says Israel Targeted Palestinian Children In Gaza

The Gaza children genocide findings were cited on Tuesday by a United Nations commission, which said…

June 23, 2026
Business

Oil Prices Fall Over 1% as Hormuz Tankers Move

Oil prices fell more than 1% on Wednesday, trading near four-month lows as more stranded tankers…

June 24, 2026
Entertainment

Meta Smart Glasses Launch With Kylie Jenner Model

Menlo Park, California: Meta smart glasses launched under the company’s own brand, including a $299 base…

June 24, 2026
Pakistan

PM Change Rumours Rejected by Rana Sanaullah

Islamabad, Pakistan: Prime Minister’s Adviser on Political Affairs Rana Sanaullah rejected PM change rumours after the…

June 20, 2026
PhotoNews Pakistan

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

    Categories

    • World
    • Pakistan
    • Punjab
    • Sindh
    • Khyber Pakhtunkhwa
    • Balochistan
    • Azad Jammu Kashmir

     

    • Top News
    • Business
    • Entertainment
    • Sports
    • Videos
    • Tech
    • Offbeat
    • Blog
    • About Us
    • Privacy Policy
    • Code of Ethics & Editorial Standards

    © 2026 Phototnews
    All Rights Reserved.

    Welcome Back!

    Sign in to your account

    Lost your password?