All verified exploits

CVE-2026-3300 Unauthenticated Remote Code Execution via Form Calculation

Deterministic critical WordPress Added cve-verified-cve-2026-3300

Detects WordPress installs running the Everest Forms Pro plugin at version 1.9.12 or earlier. The Calculation Addon's process_filter() function concatenates user-submitted form field values into a PHP code string and passes it to eval(). sanitize_text_field() does not escape single quotes, allowing unauthenticated attackers to break out of the string context and inject arbitrary PHP code — enabling full server compromise.

Related WordPress exploits

Is your app exploitable through CVE-2026-3300?

Scan your domain free