← العودة للجدول
CVE-2026-3300
Hackers Actively Exploiting WordPress Plugin Vulnerability to Inject Malicious PHP Code
📅 2026-06-04 15:01:36
🔴 Critical 🔥 No Cyber Security News Exploit Web CVSS 9.8 🎯 EPSS 0.31%

📋 الوصف الكامل

Hackers are actively exploiting a critical remote code execution (RCE) vulnerability in the Everest Forms Pro WordPress plugin, allowing unauthenticated attackers to inject and execute arbitrary PHP code on vulnerable websites. The flaw, tracked as CVE-2026-3300 with a CVSS score of 9.8, affects all versions up to 1.9.12 and has already been observed in widespread […] The post Hackers Active

💻 الأنظمة المتأثرة

WordPress | PHP

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-3300

📡 المصدر

Cyber Security News

✅ الحلول والتخفيف

Update to v1.9.12

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←