ZeroHour

CVE-2026-62103

large

Unauthenticated PHP Object Injection in Everest Forms WordPress Plugin (<= 3.6.0)

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-62103 is an unauthenticated PHP object injection vulnerability in the Everest Forms WordPress plugin, caused by deserialization of untrusted data (CWE-502). An attacker who can reach the affected code path without logging in can supply crafted serialized values, causing the plugin to instantiate arbitrary PHP objects. Depending on the object classes (gadget chains) present in a site's installed plugins, this can escalate to arbitrary file deletion, data modification, and potentially remote code execution, consistent with the assigned critical 9.8 CVSS score. All WordPress sites running Everest Forms version 3.6.0 or earlier are affected. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and there is no confirmed exploitation in the wild at this time.

What to do: Update Everest Forms to the latest available release (any version above 3.6.0) on all WordPress sites, prioritizing internet-facing sites given the unauthenticated, network-exploitable nature of the flaw. If patching must be delayed, deactivate the plugin as a stopgap and review web server and WordPress logs for suspicious unauthenticated requests or signs of object-injection abuse.

Affected
WPEverest Everest Forms (WordPress plugin)<= 3.6.0
Estimated exposure
large≈100,000+ WordPress sites (plugin's public active-install count is roughly 100k, and all installs at or below 3.6.0 are vulnerable) — Based on Everest Forms' WordPress.org active-install count of approximately 100,000, treating each active install as a potentially vulnerable site; the true vulnerable subset depends on how many run 3.6.0 or earlier.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.

Ecosystems
WordPress
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.