CVE-2026-3300

CVSS 9.8 · CRITICAL
EPSS p55
Higher than 55% of all CVEs — moderate exploitation risk.
No patch reference
No patch/mitigation in references

Published 3/31/2026 · updated 4/24/2026 · CWE-94

Share
Get asset-aware triage

Summary

The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_filter() function concatenating user-submitted form field values into a PHP code string without proper escaping before passing it to eval(). The sanitize_text_field() function applied to input does not escape single quotes or other PHP code context characters. This makes it possible for unauthenticated attackers to inject and execute arbitrary PHP code on the server by submitting a crafted value in any string-type form field (text, email, URL, select, radio) when a form uses the "Complex Calculation" feature.

CVSS 9.8CRITICAL

9.8 / 10
  • AV: Network
  • AC: Low complexity
  • PR: No privileges
  • UI: No user interaction
  • S: Scope unchanged
  • C: Confidentiality: High
  • I: Integrity: High
  • A: Availability: High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS exploitation probability

0.3%

Percentile p55 Higher than 55% of all CVEs — moderate exploitation risk.

Timeline

  1. Mar 31, 2026 · Disclosed / published in NVD
  2. Apr 24, 2026 · Intel last updated

Intel sources

Which upstream feeds returned data for this CVE, and when they were last fetched.

  • NVD· 57 days ago
  • CVE.org· no data
  • FIRST EPSS· 57 days ago
  • CISA KEV· no data
  • OSV· 57 days ago

References

Unlock the full report

See how CVE-2026-3300 hits your stack.

Free public data ends here. Sign in to correlate this CVE against your SBOM and assets, get an AI-grounded exploit chain, generate a ModSecurity virtual patch, and share findings with your team.

  • · Asset-aware CVSS & priority
  • · Grounded AI analysis (A–D graded)
  • · Auto-generated WAF / IPS rules
  • · Jira, SIEM, Slack, Teams delivery

No credit card · 100 free enrichments · analyst-grade citations.