Skip to main content
    WordPress Site Owners: Update Everest Forms Plugin Immediately to Prevent Hacking
    Cybersecurity
    Important
    2 min read

    WordPress Site Owners: Update Everest Forms Plugin Immediately to Prevent Hacking

    A security flaw in a popular WordPress form plugin has been exploited by attackers for two months. Site owners need to update now.

    Source

    SecurityWeek

    Original headline: Everest Forms Vulnerability Exploited to Hack WordPress Sites

    Plain-English summary by GetCyberRight. Read the full report at the source above.

    Published Monday, June 8, 2026Updated Monday, June 8, 20262 min read
    Share:

    A serious security vulnerability in Everest Forms, a plugin used by WordPress websites to create contact forms and surveys, has been actively exploited by hackers. The flaw allows attackers to remotely take control of websites without needing any login credentials. This exploitation has been happening in the wild for two months. If you run a WordPress website and use the Everest Forms plugin, your site could be vulnerable or may have already been compromised. Attackers can use this flaw to inject malicious code, steal visitor information, redirect users to harmful websites, or completely take over your site.

    Even if you only use your site for a small business, family blog, or community organization, it can be targeted.

    Stay one step ahead of scammers

    Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.

    Here is what you need to do right now:

    1. Log into your WordPress dashboard immediately.
    2. Go to Plugins and look for Everest Forms.
    3. Update the plugin to the latest version. If an update is available, install it immediately.
    4. If you cannot update right away, deactivate and delete the Everest Forms plugin until you can safely update it.
    5. Check your website for any unusual pages, posts, or user accounts you did not create.
    6. Consider having a web professional review your site if you are unsure whether it was compromised. Going forward, make updating your WordPress plugins a regular habit. Set a monthly reminder to check for updates, or enable automatic updates for plugins when possible. Most WordPress hacks happen because of outdated plugins, not because of sophisticated attacks. Keeping everything current is your best defense against these types of threats.

    Protect Yourself

    Use our Cyber Threat Radar to check if you're affected and take action.

    Found this useful?

    Share it with someone who could use a heads-up.

    Share:

    Curated from trusted cybersecurity sources by GetCyberRight

    Source: SecurityWeek

    Discussion

    0

    Sign in to join the discussion.

    Stay ahead of cyber threats

    Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.