Everest Forms Pro Vulnerability Allows Remote Code Execution on WordPress Sites
2026-06-04T20:52:15Z•93941ea14930344f538e747e4557cef83dfb2e1f5ff5ae8387ee9e402c1065e2
ai-generated-malwareai-threatschatgpt-abuseedr-evasioneverest-forms-proflowisegamaredonglasswormjinx-0164npmpalo-altopan-ospatchingphishingrcered-hatsilent-ransom-groupsupply-chain-compromiseta4922vulnerability-managementwordpresszero-day
What happened
Infosecurity roundup: Multiple high-impact, actively exploited vulnerabilities and supply-chain compromises were reported alongside a surge in AI-enabled threats. Key technical incidents include a critical Everest Forms Pro RCE being exploited to create rogue WordPress admin accounts, a 1-click Flowise RCE PoC that can fully compromise self-hosted servers, and a high-severity Palo Alto PAN-OS bug under active exploitation. Attackers also backdoored 32 packages in Red Hat’s npm scope to steal cloud/CI secrets, while AI-assisted malware and tooling are rising (AI-built EDR evasion tools, AI‑gen‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 93941ea14930344f538e747e4557cef83dfb2e1f5ff5ae8387ee9e402c1065e2
- Enrichment time
- 2026-06-04T20:52:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.