Everest Forms Pro Vulnerability Allows Remote Code Execution on WordPress Sites

2026-06-04T20:52:15Z93941ea14930344f538e747e4557cef83dfb2e1f5ff5ae8387ee9e402c1065e2
ai-generated-malwareai-threatschatgpt-abuseedr-evasioneverest-forms-proflowisegamaredonglasswormjinx-0164npmpalo-altopan-ospatchingphishingrcered-hatsilent-ransom-groupsupply-chain-compromiseta4922vulnerability-managementwordpresszero-day

What happened

Infosecurity roundup: Multiple high-impact, actively exploited vulnerabilities and supply-chain compromises were reported alongside a surge in AI-enabled threats. Key technical incidents include a critical Everest Forms Pro RCE being exploited to create rogue WordPress admin accounts, a 1-click Flowise RCE PoC that can fully compromise self-hosted servers, and a high-severity Palo Alto PAN-OS bug under active exploitation. Attackers also backdoored 32 packages in Red Hat’s npm scope to steal cloud/CI secrets, while AI-assisted malware and tooling are rising (AI-built EDR evasion tools, AI‑gen‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
93941ea14930344f538e747e4557cef83dfb2e1f5ff5ae8387ee9e402c1065e2
Enrichment time
2026-06-04T20:52:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.