
WordPress Sites Using Everest Forms Pro Plugin Are Being Hacked
A security flaw in a popular form plugin is letting hackers take complete control of WordPress websites. Site owners need to update immediately.
Source
BleepingComputer
Original headline: Critical Everest Forms Pro flaw exploited to take over WordPress sites
Plain-English summary by GetCyberRight. Read the full report at the source above.
Hackers are actively breaking into WordPress websites through a serious security flaw in a plugin called Everest Forms Pro. This plugin helps website owners create contact forms, registration forms, and other types of forms on their sites. The vulnerability, tracked as CVE-2026-3300 (an industry tracking number for this software flaw), allows hackers to take complete control of affected websites. This matters if you run a WordPress website that uses the Everest Forms Pro plugin. If your site has this plugin installed and you haven't updated it recently, hackers could take over your entire website. They could steal customer information, delete your content, redirect visitors to dangerous sites, or use your website to spread malware to your visitors.
If you have a WordPress website, you need to do this immediately:
- Log into your WordPress admin panel.
- Go to Plugins and look for Everest Forms Pro in your list of installed plugins.
- If you have it, update it to the latest version right away.
- If you are not sure how to do this, contact whoever helps you manage your website and ask them to check and update immediately.
- After updating, review your website's users list and remove any accounts you don't recognize. For long term website security, always keep WordPress and all your plugins updated. Set aside time once a week to check for updates, or hire someone to monitor your site's security. Consider using a security plugin that alerts you to vulnerabilities. If you run a business website or collect any customer information, regular security checks are not optional. They protect both you and the people who trust your site.
Curated from trusted cybersecurity sources by GetCyberRight
Source: BleepingComputerStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles

WordPress Website Plugin Flaw Lets Hackers Take Complete Control
A security hole in a popular WordPress form plugin is being actively exploited. If you run a WordPress site with Everest Forms Pro, take action now.
2 min read
ChatGPT Adds New Security Mode to Protect Your Private Information
OpenAI launched Lockdown Mode for ChatGPT users who share sensitive information. This feature helps prevent your data from being accidentally stolen.
2 min read
ChatGPT Adds New Privacy Protection Mode for Sensitive Information
OpenAI launched a Lockdown Mode to help prevent your private information from leaking when using ChatGPT. Here's what it does and who needs it.
2 min read
Hackers Using AI Chatbots to Break Into Instagram Accounts
Criminals are exploiting Meta's AI tools to hack Instagram accounts. Learn how to protect your family's social media from this new threat.
2 min read