
WordPress Website Plugin Flaw Lets Hackers Take Complete Control
A security hole in a popular WordPress form plugin is being actively exploited. If you run a WordPress site with Everest Forms Pro, take action now.
Source
BleepingComputer
Original headline: Critical Everest Forms Pro flaw exploited to take over WordPress sites
Plain-English summary by GetCyberRight. Read the full report at the source above.
A serious security flaw in a WordPress plugin called Everest Forms Pro is being actively exploited by hackers right now. This plugin helps website owners create contact forms and surveys. The vulnerability, labeled CVE-2026-3300 (an industry tracking number for this software flaw), allows hackers to take complete control of affected WordPress websites. This affects you if you run a WordPress website that uses the Everest Forms Pro plugin. Hackers exploiting this flaw can gain full administrative access to your website. They could change content, steal visitor information, install malicious software, or completely delete your site.
Even if you are not actively managing your WordPress site right now, it could still be vulnerable and under attack.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
If you use WordPress, take these actions immediately:
- Log into your WordPress dashboard and go to the Plugins section.
- Check if you have Everest Forms Pro installed. Look for it in your list of active plugins.
- If you have this plugin, update it immediately to the latest version. Click the update button next to the plugin name.
- If an update is not available yet, deactivate the plugin temporarily until a security patch is released.
- Review your website for any unexpected changes, new administrator accounts, or unfamiliar content.
- Consider contacting your web hosting provider for additional security scanning and support. Keep all WordPress plugins, themes, and the WordPress software itself updated regularly. Outdated plugins are one of the most common ways hackers break into websites. Set a monthly reminder to check for updates, or enable automatic updates for trusted plugins. If you have not logged into your WordPress site in months, do so today to check for critical security updates.
Curated from trusted cybersecurity sources by GetCyberRight
Source: BleepingComputerStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles

WordPress Sites Using Everest Forms Pro Plugin Are Being Hacked
A security flaw in a popular form plugin is letting hackers take complete control of WordPress websites. Site owners need to update immediately.
2 min read
ChatGPT Adds New Security Mode to Protect Your Private Information
OpenAI launched Lockdown Mode for ChatGPT users who share sensitive information. This feature helps prevent your data from being accidentally stolen.
2 min read
ChatGPT Adds New Privacy Protection Mode for Sensitive Information
OpenAI launched a Lockdown Mode to help prevent your private information from leaking when using ChatGPT. Here's what it does and who needs it.
2 min read
Hackers Using AI Chatbots to Break Into Instagram Accounts
Criminals are exploiting Meta's AI tools to hack Instagram accounts. Learn how to protect your family's social media from this new threat.
2 min read