Form submission

Remote Code Execution in Everest Forms

CVE-2026-3300 is a critical unauthenticated RCE in Everest Forms ≤1.9.12 — the Calculation Addon passes user input directly to eval(), giving attackers full server access.

26 June 2026

Read more

Arbitrary file move in MW WP Form lets attackers take over your site

MW WP Form versions up to and including 5.1.0 have a path traversal vulnerability that let attackers completely take over your site. It's a common pattern, with this plugin when file uploads are enabled.

3 April 2026

Read more