A critical vulnerability in the Everest Forms Pro plugin is being actively exploited, allowing attackers to seize control of vulnerable WordPress websites.

Security researchers have observed ongoing attacks targeting the flaw, which enables unauthenticated threat actors to create administrator accounts without valid credentials. Once attackers gain administrative access, they can modify site content, install malicious plugins, deploy malware, or maintain long-term access to compromised websites.

The discovery has prompted urgent warnings for WordPress administrators running affected versions of the popular form-building plugin.

Vulnerability Enables Full Site Takeover

The Everest Forms flaw affects the premium version of the plugin and carries a critical severity rating.

According to researchers, attackers can abuse the vulnerability to bypass normal authentication mechanisms and create new administrator accounts on vulnerable sites. Because administrator privileges provide complete control over a WordPress installation, successful exploitation can quickly lead to a full compromise.

Unlike attacks that require stolen credentials, this vulnerability can be exploited remotely without prior access to the website.

That significantly increases the risk for internet-facing WordPress installations that remain unpatched.

Active Exploitation Already Underway

Researchers reported that threat actors began targeting the flaw shortly after details became public.

The attacks focus on identifying vulnerable websites and automatically creating rogue administrator accounts. Once access is established, attackers can use the compromised site for a variety of malicious purposes.

Some may deploy malware or redirect visitors to fraudulent pages. Others may use the compromised website as part of a larger attack infrastructure.

The speed of the exploitation highlights how quickly cybercriminals weaponize newly disclosed WordPress vulnerabilities.

WordPress Plugins Remain a Popular Target

WordPress powers a significant portion of the internet, making its plugin ecosystem a frequent target for attackers.

Many website compromises originate through vulnerable plugins that provide additional functionality but may also introduce security weaknesses. Form-building plugins are particularly attractive because they often process user input and interact with sensitive website functions.

Security experts recommend minimizing unnecessary plugins and applying updates as soon as they become available.

Regular security reviews can also help identify outdated components before attackers exploit them.

Site Owners Should Patch Immediately

The plugin developer has released updates that address the vulnerability.

Website administrators should install the latest version as soon as possible and review user accounts for unauthorized administrator profiles. Security teams should also examine logs for unusual account creation activity and investigate any signs of compromise.

Organizations that delay patching may leave their websites exposed to ongoing attacks.

Conclusion

The Everest Forms flaw demonstrates how a single vulnerable plugin can place an entire WordPress website at risk. By allowing attackers to create administrator accounts without authentication, the vulnerability provides a direct path to complete site takeover.

With active exploitation already underway, affected organizations should prioritize patching and review their environments for signs of unauthorized access before attackers can establish a lasting foothold.


0 responses to “Everest Forms Flaw Lets Attackers Take Over WordPress Sites”