Everest Forms Pro WordPress Flaw is Handing Attackers Admin Access
2026-06-08T20:51:45Z•5bd56001ee864ed03e41d480ff9214217d88fe55fec861ac3b0a7611588afd73
C0XMOCVE-2021-27137CVE-2026-28318','CISA-KEV'CVE-2026-3300DDoSDentaQuestEverest FormsGafgytHTSInstagramIoTMetaPIIShinyHuntersSolarWindsUNC3753account-takeoverbotnetdata-breachextortionphp-injectionphysical-intrusionprivilege-escalationvishingwordpress
What happened
This Security Affairs feed highlights multiple high-impact security incidents: a PHP injection in Everest Forms Pro (CVE-2026-3300) allowed attackers to create rogue WordPress admin accounts (patch released; ~29,300 attack attempts blocked); UNC3753 (aka Luna Moth/Chatty Spider) escalated from vishing and screen-hijacks to in-person office intrusions and planted USBs in extortion campaigns against US legal and financial firms; a flaw in Meta’s Instagram recovery/HTS tool exposed 20,000+ accounts enabling account takeovers; the new IoT botnet C0XMO (Gafgyt variant) exploits old router flaws (e.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 5bd56001ee864ed03e41d480ff9214217d88fe55fec861ac3b0a7611588afd73
- Enrichment time
- 2026-06-08T20:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.