By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
MadisonyMadisony
Notification Show More
Font ResizerAa
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Reading: Critical WordPress Plugin Flaw Allows Full Site Hijacking
Share
Font ResizerAa
MadisonyMadisony
Search
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Have an existing account? Sign In
Follow US
2025 © Madisony.com. All Rights Reserved.
Technology

Critical WordPress Plugin Flaw Allows Full Site Hijacking

Madisony
Last updated: June 9, 2026 5:16 am
Madisony
Share
Critical WordPress Plugin Flaw Allows Full Site Hijacking
SHARE

Security experts are sounding the alarm about an active cyberattack campaign targeting WordPress websites. A critical vulnerability within the popular Everest Forms Pro plugin is reportedly being exploited, allowing attackers to gain complete control of affected sites.

Contents
Severe Vulnerability Puts WordPress Sites at RiskImpact of Account TakeoverExploitation and Patching TimelineRecommendations for Site Administrators

Severe Vulnerability Puts WordPress Sites at Risk

The flaw, identified as CVE-2026-3300, is a Remote Code Execution (RCE) vulnerability that enables attackers to inject PHP code into vulnerable websites. This allows them to create rogue administrator accounts, effectively hijacking the entire site. The vulnerability has been assigned a critical severity rating of 9.8 out of 10.

The exploit works by submitting a specially crafted value to a text field within the form. This input is designed to close the existing string literal and then execute a PHP statement that calls the `wp_insert_user()` function. This function is used to create a new administrator account, with recent attacks creating an account named “diksimarina”. A trailing comment marker is used to ensure the injected code is executed without causing syntax errors.

Impact of Account Takeover

Gaining administrator privileges on a WordPress site grants attackers extensive capabilities. They can potentially steal sensitive files, redirect website visitors to malicious destinations, or distribute malware. This poses a significant threat to website owners and their users.

Exploitation and Patching Timeline

The vulnerability was initially disclosed in February of this year. Developers released a patch for Everest Forms Pro by mid-March. However, exploitation attempts reportedly began around mid-April, approximately a month after the fix became available.

Analysis indicates that nearly 30,000 attempted attacks have been thwarted. A significant portion of these attempts have been traced back to two specific IP addresses: 202.56.2[.]126 and 209.146.60.26.

Recommendations for Site Administrators

Website administrators who use Everest Forms Pro are strongly advised to update their plugin to the latest version immediately to patch this critical vulnerability. To further enhance security, it is recommended to block the identified malicious IP addresses at the server level. Additionally, site owners should review their website’s log files for any occurrences of the username “diksimarina” to detect potential compromises.

Subscribe to Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
[mc4wp_form]
Share This Article
Email Copy Link Print
Previous Article ABC News Chief Unaware of Replacement Before Resignation ABC News Chief Unaware of Replacement Before Resignation
Next Article Trump Met With Boos and Chants at NBA Finals Game 3 Trump Met With Boos and Chants at NBA Finals Game 3

POPULAR

UK Braces for 30C Heatwave After Week of Rain
top

UK Braces for 30C Heatwave After Week of Rain

YouTube’s BreadTube: A Counter-Movement to Online Extremism
Politics

YouTube’s BreadTube: A Counter-Movement to Online Extremism

Trump Met With Boos and Chants at NBA Finals Game 3
world

Trump Met With Boos and Chants at NBA Finals Game 3

Critical WordPress Plugin Flaw Allows Full Site Hijacking
Technology

Critical WordPress Plugin Flaw Allows Full Site Hijacking

ABC News Chief Unaware of Replacement Before Resignation
business

ABC News Chief Unaware of Replacement Before Resignation

Ariana Grande and Ethan Slater End Relationship After Three Years
Entertainment

Ariana Grande and Ethan Slater End Relationship After Three Years

Hilarious Internet Finds: 63 Moments That Sparked Laughter
top

Hilarious Internet Finds: 63 Moments That Sparked Laughter

You Might Also Like

Why China Builds Quicker Than the Remainder of the World
Technology

Why China Builds Quicker Than the Remainder of the World

And that requires swallowing our satisfaction right here, proper? Like we really have to study from China, despite the fact…

4 Min Read
Social media bans needs to be for everybody
Technology

Social media bans needs to be for everybody

It was the final day of college earlier than winter break, and Aiden and his eighth-grade classmates had been enjoying…

10 Min Read
35 Greatest Household Board Video games (2025): Catan, Ticket to Experience, Codenames
Technology

35 Greatest Household Board Video games (2025): Catan, Ticket to Experience, Codenames

Extra Household Board Video games{Photograph}: Simon HillThere are such a lot of household board video games. Listed below are just…

8 Min Read
The 4 Greatest Invisible Listening to Aids of 2025, Examined and Reviewed
Technology

The 4 Greatest Invisible Listening to Aids of 2025, Examined and Reviewed

Invisible Listening to Aids to Keep away fromInvisible or not, the market is turning into saturated with low-quality listening to…

8 Min Read
Madisony

We cover the stories that shape the world, from breaking global headlines to the insights behind them. Our mission is simple: deliver news you can rely on, fast and fact-checked.

Recent News

UK Braces for 30C Heatwave After Week of Rain
UK Braces for 30C Heatwave After Week of Rain
June 9, 2026
YouTube’s BreadTube: A Counter-Movement to Online Extremism
YouTube’s BreadTube: A Counter-Movement to Online Extremism
June 9, 2026
Trump Met With Boos and Chants at NBA Finals Game 3
Trump Met With Boos and Chants at NBA Finals Game 3
June 9, 2026

Trending News

UK Braces for 30C Heatwave After Week of Rain
YouTube’s BreadTube: A Counter-Movement to Online Extremism
Trump Met With Boos and Chants at NBA Finals Game 3
Critical WordPress Plugin Flaw Allows Full Site Hijacking
ABC News Chief Unaware of Replacement Before Resignation
  • About Us
  • Privacy Policy
  • Terms Of Service
Reading: Critical WordPress Plugin Flaw Allows Full Site Hijacking
Share

2025 © Madisony.com. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?