Remote Code Execution in Everest Forms
CVE-2026-3300 is a critical unauthenticated RCE in Everest Forms ≤1.9.12 — the Calculation Addon passes user input directly to eval(), giving attackers full server access.
26 June 2026
Read moreArbitrary file move in MW WP Form lets attackers take over your site
MW WP Form versions up to and including 5.1.0 have a path traversal vulnerability that let attackers completely take over your site. It's a common pattern, with this plugin when file uploads are enabled.
3 April 2026
Read more