By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
MadisonyMadisony
Notification Show More
Font ResizerAa
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Reading: Critical WordPress Plugin Flaw Allows Full Site Hijacking
Share
Font ResizerAa
MadisonyMadisony
Search
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Have an existing account? Sign In
Follow US
2025 © Madisony.com. All Rights Reserved.
Technology

Critical WordPress Plugin Flaw Allows Full Site Hijacking

Madisony
Last updated: June 9, 2026 5:16 am
Madisony
Share
Critical WordPress Plugin Flaw Allows Full Site Hijacking
SHARE

Security experts are sounding the alarm about an active cyberattack campaign targeting WordPress websites. A critical vulnerability within the popular Everest Forms Pro plugin is reportedly being exploited, allowing attackers to gain complete control of affected sites.

Contents
Severe Vulnerability Puts WordPress Sites at RiskImpact of Account TakeoverExploitation and Patching TimelineRecommendations for Site Administrators

Severe Vulnerability Puts WordPress Sites at Risk

The flaw, identified as CVE-2026-3300, is a Remote Code Execution (RCE) vulnerability that enables attackers to inject PHP code into vulnerable websites. This allows them to create rogue administrator accounts, effectively hijacking the entire site. The vulnerability has been assigned a critical severity rating of 9.8 out of 10.

The exploit works by submitting a specially crafted value to a text field within the form. This input is designed to close the existing string literal and then execute a PHP statement that calls the `wp_insert_user()` function. This function is used to create a new administrator account, with recent attacks creating an account named “diksimarina”. A trailing comment marker is used to ensure the injected code is executed without causing syntax errors.

Impact of Account Takeover

Gaining administrator privileges on a WordPress site grants attackers extensive capabilities. They can potentially steal sensitive files, redirect website visitors to malicious destinations, or distribute malware. This poses a significant threat to website owners and their users.

Exploitation and Patching Timeline

The vulnerability was initially disclosed in February of this year. Developers released a patch for Everest Forms Pro by mid-March. However, exploitation attempts reportedly began around mid-April, approximately a month after the fix became available.

Analysis indicates that nearly 30,000 attempted attacks have been thwarted. A significant portion of these attempts have been traced back to two specific IP addresses: 202.56.2[.]126 and 209.146.60.26.

Recommendations for Site Administrators

Website administrators who use Everest Forms Pro are strongly advised to update their plugin to the latest version immediately to patch this critical vulnerability. To further enhance security, it is recommended to block the identified malicious IP addresses at the server level. Additionally, site owners should review their website’s log files for any occurrences of the username “diksimarina” to detect potential compromises.

Subscribe to Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
[mc4wp_form]
Share This Article
Email Copy Link Print
Previous Article ABC News Chief Unaware of Replacement Before Resignation ABC News Chief Unaware of Replacement Before Resignation
Next Article Trump Met With Boos and Chants at NBA Finals Game 3 Trump Met With Boos and Chants at NBA Finals Game 3

POPULAR

YouTube’s BreadTube: A Counter-Movement to Online Extremism
Politics

YouTube’s BreadTube: A Counter-Movement to Online Extremism

Trump Met With Boos and Chants at NBA Finals Game 3
world

Trump Met With Boos and Chants at NBA Finals Game 3

Critical WordPress Plugin Flaw Allows Full Site Hijacking
Technology

Critical WordPress Plugin Flaw Allows Full Site Hijacking

ABC News Chief Unaware of Replacement Before Resignation
business

ABC News Chief Unaware of Replacement Before Resignation

Ariana Grande and Ethan Slater End Relationship After Three Years
Entertainment

Ariana Grande and Ethan Slater End Relationship After Three Years

Hilarious Internet Finds: 63 Moments That Sparked Laughter
top

Hilarious Internet Finds: 63 Moments That Sparked Laughter

NBA Finals Chaos: Security Delays Frustrate Fans at Madison Square Garden
Sports

NBA Finals Chaos: Security Delays Frustrate Fans at Madison Square Garden

You Might Also Like

Save £542 on Car Insurance: Renew 28 Days Early
Technology

Save £542 on Car Insurance: Renew 28 Days Early

Drivers can slash their annual car insurance costs by up to £542 using a straightforward 28-day renewal strategy. Petrol, diesel,…

2 Min Read
The enterprise voice AI cut up: Why structure — not mannequin high quality — defines your compliance posture
Technology

The enterprise voice AI cut up: Why structure — not mannequin high quality — defines your compliance posture

For the previous yr, enterprise decision-makers have confronted a inflexible architectural trade-off in voice AI: undertake a "Native" speech-to-speech (S2S)…

13 Min Read
There Aren’t a Lot of Causes to Get Excited A few New Amazon Smartphone
Technology

There Aren’t a Lot of Causes to Get Excited A few New Amazon Smartphone

“This isn't a shopper system firm that takes privateness very critically,” Gamero-Garrido says. Since folks use smartphones excess of Alexa…

3 Min Read
Eight Murder Suspects Escape Louisiana Jail in Dramatic Breakout
businesscrimeEducationEntertainmentHealthPoliticsSportsTechnologytopworld

Eight Murder Suspects Escape Louisiana Jail in Dramatic Breakout

Manhunt Ends with All Eight Fugitives CapturedA massive search operation concluded successfully after eight inmates, including three facing murder charges,…

3 Min Read
Madisony

We cover the stories that shape the world, from breaking global headlines to the insights behind them. Our mission is simple: deliver news you can rely on, fast and fact-checked.

Recent News

YouTube’s BreadTube: A Counter-Movement to Online Extremism
YouTube’s BreadTube: A Counter-Movement to Online Extremism
June 9, 2026
Trump Met With Boos and Chants at NBA Finals Game 3
Trump Met With Boos and Chants at NBA Finals Game 3
June 9, 2026
Critical WordPress Plugin Flaw Allows Full Site Hijacking
Critical WordPress Plugin Flaw Allows Full Site Hijacking
June 9, 2026

Trending News

YouTube’s BreadTube: A Counter-Movement to Online Extremism
Trump Met With Boos and Chants at NBA Finals Game 3
Critical WordPress Plugin Flaw Allows Full Site Hijacking
ABC News Chief Unaware of Replacement Before Resignation
Ariana Grande and Ethan Slater End Relationship After Three Years
  • About Us
  • Privacy Policy
  • Terms Of Service
Reading: Critical WordPress Plugin Flaw Allows Full Site Hijacking
Share

2025 © Madisony.com. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?