CVE-2026-62103

9.8

wpeverest · Everest Forms

Everest Forms for WordPress contains an unauthenticated PHP object injection vulnerability in versions 3.6.0 and earlier, potentially allowing remote code execution.

Executive summary

A critical unauthenticated PHP object injection flaw in the Everest Forms plugin could allow remote attackers to achieve full system compromise.

Vulnerability

This is a deserialization of untrusted data (CWE-502) vulnerability occurring in the Everest Forms plugin. It allows an unauthenticated attacker to inject malicious PHP objects, which can lead to remote code execution, unauthorized data access, or denial of service.

Business impact

The CVSS score of 9.8 reflects the high severity of this vulnerability, as it requires no authentication and can be exploited remotely by an attacker. Successful exploitation could lead to total system compromise, including the theft of sensitive user data, unauthorized modification of site content, or the complete disruption of business operations.

Remediation

Immediate Action: Update the WordPress Everest Forms plugin to version 3.6.1 or the latest available version immediately.

Proactive Monitoring: Review web server access logs for anomalous requests, particularly those targeting the Everest Forms plugin endpoints or containing serialized PHP data structures.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block malicious deserialization attempts or common PHP object injection payloads.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability presents a severe risk to any WordPress environment utilizing the Everest Forms plugin. Administrators must prioritize updating the plugin to version 3.6.1 or newer immediately to neutralize the threat. Failure to patch allows for unauthenticated remote code execution, which could result in a complete loss of site integrity and data confidentiality.

More wpeverest CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources

Originally found and disclosed by LueRader | Patchstack Bug Bounty Program, per the CVE Program record.