Everest Forms Pro, a WordPress plugin with around 4,000 active installations, has a critical Remote Code Execution vulnerability that is currently being exploited by attackers. Site owners must update to version 1.9.13 immediately to prevent potential site compromise.
Vulnerability Details
The vulnerability allows unauthenticated attackers to execute arbitrary PHP code on the server by exploiting the Calculation Addon’s process_filter() function. This issue affects all versions up to 1.9.12. The vendor released a patched version (1.9.13) on March 18, 2026, but attackers began exploiting the flaw as early as April 13, 2026.
Recommended Actions
Site owners should update to the latest version of Everest Forms Pro (1.9.13) without delay. Additionally, monitor your site for any unusual activity, especially if you have not yet updated.
Attack Statistics
Since the vulnerability was disclosed, the Wordfence Firewall has blocked over 29,300 exploit attempts targeting this issue. This highlights the urgency of updating your plugin to avoid being compromised.
Frequently Asked Questions
What version of Everest Forms Pro is vulnerable?
Versions <= 1.9.12 are vulnerable to the Remote Code Execution issue.
When was the patched version of Everest Forms Pro released?
The patched version 1.9.13 was released on March 18, 2026.
How can I protect my site from this vulnerability?
Update to Everest Forms Pro version 1.9.13 as soon as possible to mitigate the risk.