Detects WordPress installs running the Everest Forms Pro plugin at version 1.9.12 or earlier. The Calculation Addon's process_filter() function concatenates user-submitted form field values into a PHP code string and passes it to eval(). sanitize_text_field() does not escape single quotes, allowing unauthenticated attackers to break out of the string context and inject arbitrary PHP code — enabling full server compromise.
Is your app exploitable through CVE-2026-3300?
Scan your domain free