Close Menu
  • Tech Insights
  • Laptops
  • Mobiles
  • Gaming
  • Apps
  • Money
  • Latest in Tech
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
TechzLab – Tech News, Gadgets, Mobile, IT Updates & ReviewsTechzLab – Tech News, Gadgets, Mobile, IT Updates & Reviews
  • Tech Insights
  • Laptops
  • Mobiles
  • Gaming
  • Apps
  • Money
  • Latest in Tech
TechzLab – Tech News, Gadgets, Mobile, IT Updates & ReviewsTechzLab – Tech News, Gadgets, Mobile, IT Updates & Reviews
Home » WordPress users beware — experts claim sites are being hijacked using a critical flaw in popular Everest Forms Pro plugin
Laptops

WordPress users beware — experts claim sites are being hijacked using a critical flaw in popular Everest Forms Pro plugin

By June 9, 2026No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email

  • Critical RCE flaw in Everest Forms Pro (CVE‑2026‑3300) actively exploited
  • Attackers create rogue admin account “diksimarina” via PHP injection
  • Nearly 30,000 takeover attempts blocked; admins urged to patch and block key IPs

Security researchers are warning of an ongoing hacking campaign targeting certain WordPress websites using a popular plugin tool.

Wordfence has claimed Everest Forms Pro, a popular WordPress plugin, was allegedly being used to create contract, registration, payment, and other application forms, carried a critical-severity vulnerability that allowed malicious actors to take over the sites entirely.

The bug was described as a Remote Code Execution (RCE) flaw via PHP code injection. It is tracked as CVE-2026-3300 and was given the severity rating of 9.8/10 (critical). It affects all versions of the plugin up to, and including, 1.9.12.

Latest Videos From

Patched months ago

Wordfence is now warning that the flaw is being actively abused in the wild to create malicious admin accounts on vulnerable websites:

“The attacker submits a value for a text field that begins with a single quote to close the wrapping string literal, followed by a PHP statement that calls wp_insert_user() to create a new administrator account with the username ‘diksimarina’,” Wordfence warned in its report.

You may like

“The trailing // comment marker ensures the rest of the generated PHP code, including the closing quote, is treated as a comment and does not cause a syntax error.” “When the form is processed, and the calculation is evaluated, the injected PHP code is executed, and the malicious administrator account is created.”

By creating an admin account, malicious actors can do almost anything with the website, including exfiltrating stored files, redirecting visitors, or even serving malware.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

The bug was first disclosed in February this year, and by mid-March, the Everest Forms developer released a fix. Wordfence says that exploitation attempts started roughly a month later, in mid-April. So far, it thwarted almost 30,000 attempts, most of which came from two IP addresses.

Admins worried about being potential targets should block the two IP addresses 202.56.2[.]126 and 209.146.60.26, and should review log files for the string “diksimarina.”

Via BleepingComputer


Best antivirus software header

The best antivirus for all budgets

Our top picks, based on real-world testing and comparisons

Google logo on a black background next to text reading 'Click to follow TechRadar'

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.


Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Friday’s papers: University tells academics to avoid US, Finland’s athlete shortage, and slippery streets – Yle

June 8, 2026

NYT Strands hints and answers for Sunday, June 7 (game #826)

June 7, 2026

Unpatched Windows search URI handler issue leaks NTLMv2 hashes – SC Media

June 6, 2026
Leave A Reply Cancel Reply

Comment moderation is enabled. Your comment may take some time to appear.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest
  • Zepto’s IPO filing reveals fast growth, bigger losses, and a valuation question nobody’s answered yet | TechCrunch June 9, 2026
  • Google Reportedly Wants Android App Code From Play Store Developers June 9, 2026
  • What It Can Track and What It Can’t June 9, 2026
  • TikTok reports ‘major infrastructure issue’ causing app glitches, bugs – ZDNET June 9, 2026
  • WordPress users beware — experts claim sites are being hijacked using a critical flaw in popular Everest Forms Pro plugin June 9, 2026
We are social
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo

Subscribe to Updates

Get the latest creative news from Techzlab.

Tags
AI Amazon Anthropic Apple artificial intelligence Benchmark Partners ChatGPT cybersecurity data centers defense tech Donald Trump electric vehicles Elon Musk Equity podcast evergreens EVs Exclusive gemini Google Grok In Brief India Layoffs Meta Microsoft nvidia nvidia gtc Nvidia GTC 2026 Openai Perplexity Polymarket robotaxi robotics Sequoia Capital Softbank SpaceX Spotify Tesla Trump Administration Uber venture venture capital Voice Ai Windows YouTube
Archives
Quick Link
  • Apps (356)
  • From the Editor (4)
  • Gaming (344)
  • Laptops (358)
  • Latest in Tech (356)
  • Mobiles (358)
  • Money (181)
  • Tech Insights (357)
Don't miss

Faster iPhones, New Safety Features, and More

June 9, 2026

WWDC 2026 Live: Apple’s New Siri, iOS 27, Tim Cook and More

June 8, 2026

Years of emergency prep taught me how to storm-proof my solar generators

June 7, 2026
Follow us
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
© 2026 Techzlab.com Designed and Developed by WebExpert.
  • Home
  • From the Editor
  • Money
  • Privacy Policy
  • Contact

Type above and press Enter to search. Press Esc to cancel.