Tag Archives: code injections

The Three-Month Fuse: The Everest Forms Pro Attack and Why a Patched Plugin Can Still Put Websites at Risk

Illustration showing a cyber attack bypassing a security shield to compromise a website.

A critical vulnerability in Everest Forms Pro is a good example of a problem that goes beyond one WordPress plugin.

The vulnerability, tracked as CVE-2026-3300, allowed an unauthenticated attacker to execute arbitrary PHP code on a WordPress site. The flaw is rated critical, with a CVSS score of 9.8 out of 10.

The developer released version 1.9.13 on March 18, 2026, to fix the problem.

That should have been the end of it.

It wasn't.

Attackers began actively exploiting the

... Continue reading
Posted in Coding, Server Admin & Security | Tagged , , , , , , , , , , , , , , , | Leave a comment

Beyond the Hype: The Systemic Security Risk in AI Agents

AI agents, systemic security risk

If you follow tech news, you might have heard about a "zero-click" flaw in Claude’s desktop app back in February. But as of April 2026, this story has evolved from a single app's problem into a systemic warning for the entire AI industry.

The Latest: The MCP SDK Flaw

Recent investigations have confirmed that the vulnerability isn't just a "bug" in one software version. It is built into the Model Context Protocol (MCP) SDK itself. This is the official

... Continue reading
Posted in Technology in the News, Website Security | Tagged , , , , , , , , , , , , | Leave a comment