{"id":1177,"date":"2026-06-05T09:02:35","date_gmt":"2026-06-05T09:02:35","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1177"},"modified":"2026-06-05T09:02:35","modified_gmt":"2026-06-05T09:02:35","slug":"hackers-exploit-critical-everest-forms-pro-wordpress-plugin-flaw-to-take-over-sites","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1177","title":{"rendered":"Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjgKOwHRwFSrcOI7vBYVGbebtc3DwR3w7SYc9l7FUXp1yXc_N2MbNNlEXtfRjVneU4wz2YB8PqC_k54o_6ZpB2oKZKhVBlK7IC-CGU05B5GgE7qS26MBxKIWLZTC2rNhVf2vufJcwh7RK4zuH-twWCcd_eZtNm25Pmn-pQyOXcB7N_C9918yOP7C1K4KrNz\/s1700-e365\/wordpress.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site compromise.<\/p>\n<p>The vulnerability in question is CVE-2026-3300 (CVSS score: 9.8), a remote code execution bug impacting all versions of the plugin up to, and including, 1.9.12. A patch for the flaw was released on March 18, 2026, with version 1.9.13.<\/p>\n<p>\u00abThis is due to the Calculation Addon&#8217;s process_filter() function concatenating user-submitted form field values into a PHP code string without proper escaping before passing it to eval(),\u00bb Wordfence <a href=\"https:\/\/www.wordfence.com\/blog\/2026\/06\/attackers-actively-exploiting-critical-vulnerability-in-everest-forms-pro-plugin\/\">said<\/a>.<\/p>\n<p>\u00abThe sanitize_text_field() function applied to input does not escape single quotes or other PHP code context characters. This makes it possible for unauthenticated attackers to inject and execute arbitrary PHP code on the server by submitting a crafted value in any string-type form field (text, email, URL, select, radio) when a form uses the &#8216;Complex Calculation&#8217; feature.\u00bb<\/p>\n<p>Successful exploitation of the vulnerability could allow unauthenticated bad actors to execute arbitrary PHP code on the server, permitting them to create rogue administrator accounts, deploy web shells, and open other ways to burrow deeper into the server and establish persistent footholds.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>According to the WordPress security company, attackers have been observed exploiting the flaw starting April 13, 2026. More than 29,300 exploit attempts targeting the defect have been blocked to date. Of these, <a href=\"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/everest-forms-pro\/everest-forms-pro-1912-unauthenticated-remote-code-execution-via-calculation-field\">16 attack attempts<\/a> occurred in the last 24 hours. The most common payload involves attempts to create an administrator account named \u00abdiksimarina\u00bb (email address: diksimarina@gmail.com) on the compromised site.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>These attack efforts have originated from the following IP addresses &#8211;<\/p>\n<ul>\n<li>202.56.2.126<\/li>\n<li>209.146.60.26<\/li>\n<li>15.235.166.18<\/li>\n<li>2402:1f00:8000:800::40db<\/li>\n<li>185.78.165.153<\/li>\n<\/ul>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgWRR8U6PCTO5cxgK4VyQ21XWDJA0hX9oXeLkd5FvxG0UazqVyY4FaRnnleUQcUBaT5j0LtYJ2ODJjx2MP4ckM05XL8C_-Ax8wzJbX8Qzful4fwRWg5UwwNTzCQbNHZlg4jT_ikITO2qRTq7eQKg3CUj1tUjoXjnE6E_V4srzZXUqPvrfrBK38kijJw4oyu\/s1700-e365\/wordfence.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgWRR8U6PCTO5cxgK4VyQ21XWDJA0hX9oXeLkd5FvxG0UazqVyY4FaRnnleUQcUBaT5j0LtYJ2ODJjx2MP4ckM05XL8C_-Ax8wzJbX8Qzful4fwRWg5UwwNTzCQbNHZlg4jT_ikITO2qRTq7eQKg3CUj1tUjoXjnE6E_V4srzZXUqPvrfrBK38kijJw4oyu\/s1700-e365\/wordfence.png\" alt=\"\" border=\"0\" data-original-height=\"755\" data-original-width=\"985\"\/><\/a><\/div>\n<h3>Skimmer Attacks Exploit Stripe for C2<\/h3>\n<p>The disclosure comes as Sansec warned of multiple skimmer campaigns, including one that uses Stripe as a command-and-control (C2) server and a data exfiltration sink in a bid to exploit the reputation of the brand and slip past Content Security Policy rules and network filters.<\/p>\n<p>\u00abThe attacker treats Stripe as free infrastructure, not a way to launder charges,\u00bb Sansec <a href=\"https:\/\/sansec.io\/research\/stripe-api-skimmer-infrastructure\">noted<\/a>. \u00abStripe gives them a writable database for stolen cards and a code-hosting endpoint for the skimmer, both behind a domain that CSP rules and network filters trust by default.\u00bb<\/p>\n<p>The campaign relies on Google Tag Manager (GTM) and Stripe domains &#8211; googletagmanager.com and api.stripe.com &#8211; which are both trusted implicitly by online stores, with the malicious code loaded from a GTM container and executed on every page that loads it.<\/p>\n<p>On Magento and Adobe Commerce checkout pages, it extracts an obfuscated skimmer from a <a href=\"https:\/\/docs.stripe.com\/api\/customers\/\">Stripe customer account<\/a>&#8216;s (\u00abcus_TfFjAAZQNOYENR,\u00bb in this case) metadata field, and saves the financial information, billing and email addresses, and phone numbers entered by unsuspecting users to <a href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/API\/Window\/localStorage\">localStorage<\/a>. The captured data is then exfiltrated back to the attacker&#8217;s Stripe account.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abEvery stolen card becomes a &#8216;customer&#8217; in the attacker&#8217;s account,\u00bb the e-commerce security company said. \u00abOn success, the loader deletes the localStorage entry, so the same record is not sent twice. The attacker lists their stolen cards later by calling the same API with the same key. Stripe&#8217;s customer database becomes a free, durable exfiltration sink.\u00bb<\/p>\n<p>The Stripe customer record containing the skimmer is said to have been created on December 24, 2025, indicating that the operation may have been active since then. Sansec said it also identified a second variant of the loader that uses Google Firestore instead of Stripe, although the end goal is the same: abuse a trusted service as a covert channel that&#8217;s unlikely to be blocked by e-commerce stores.<\/p>\n<p>The findings coincide with a large-scale operation dubbed <a href=\"https:\/\/sansec.io\/research\/gorgonagora-fake-storefront-skimming-network\">GorgonAgora<\/a> that has used a cluster of 5,714 fake .shop storefronts impersonating brands like Starbucks, Ford, Sony, Mattel, Hasbro, Lego, Disney, and Toyota, whose checkout pages funnel stolen card data to a single skimmer server in Moldova. The campaign has been ongoing since August 2025.<\/p>\n<p>\u00abEvery store runs the same Medusa.js commerce stack and loads the same custom checkout SDK, which renders a fake Stripe iframe and exfiltrates card data over an encrypted WebSocket to a single server in Moldova,\u00bb the Dutch company said.<\/p>\n<p>\u00abExfiltration runs over WebSocket with an AES-256-GCM payload, and the C2 maintains a live 3D Secure relay: when the victim bank returns a 3DS challenge, the operator proxies it back to the shopper through the fake iframe so the transaction completes and the theft stays invisible.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1178,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[58,1925,120,70,1926,338,1258,1156,228,1927],"class_list":["post-1177","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-critical","tag-everest","tag-exploit","tag-flaw","tag-forms","tag-hackers","tag-plugin","tag-pro","tag-sites","tag-wordpress"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1177","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1177"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1177\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1178"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1177"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1177"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1177"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}