Vulnerabilities
WordPress and Magento Plugin RCE Keeps Coming: Everest Forms Exploited, Mirasvit Added to KEV
Two more plugin RCEs are under active exploitation: Everest Forms Pro CVE-2026-3300 (CVSS 9.8), a PHP-injection flaw Wordfence has blocked tens of thousands of times, and Magento's Mirasvit Cache Warmer CVE-2026-45247 (CVSS 9.8), now added to CISA's KEV catalog.