CVE-2026-3296
published 2026-04-08CVE-2026-3296: The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input…
PriorityP182critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
3.47%
88.3th percentile
The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling PHP's native unserialize() on stored entry meta values without passing the allowed_classes parameter. This makes it possible for unauthenticated attackers to inject a serialized PHP object payload through any public Everest Forms form field. The payload survives sanitize_text_field() sanitization (serialization control characters are not stripped) and is stored in the wp_evf_entrymeta database table. When an administrator views entries or views an individual entry, the unsafe unserialize() call processes the stored data without class restrictions.
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
wpeverest Everest Forms Plugin up to 3.4.3 on WordPress html-admin-page-entries-view.php unserialize deserialization
vuldb·2026-07-28·CVSS 9.8
CVE-2026-3296 [CRITICAL] wpeverest Everest Forms Plugin up to 3.4.3 on WordPress html-admin-page-entries-view.php unserialize deserialization
A vulnerability classified as critical was found in wpeverest Everest Forms Plugin up to 3.4.3 on WordPress. This issue affects the function unserialize of the file html-admin-page-entries-view.php. Such manipulation leads to deserialization.
This vulnerability is traded as CVE-2026-3296. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
GHSA
GHSA-rc2g-jh8w-mqh9: The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3
ghsa_unreviewed·2026-04-08
CVE-2026-3296 [CRITICAL] CWE-502 GHSA-rc2g-jh8w-mqh9: The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3
The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling PHP's native unserialize() on stored entry meta values without passing the allowed_classes parameter. This makes it possible for unauthenticated attackers to inject a serialized PHP object payload through any public Everest Forms form field. The payload survives sanitize_text_field() sanitization (serialization control characters are not stripped) and is stored in the wp_evf_entrymeta database table. When an administrator views entries or views an individual entry, the unsafe unserialize() call processes the stored data without class restricti
VulnCheck
wpeverest everest_forms Deserialization of Untrusted Data
vulncheck·2026·CVSS 9.8
CVE-2026-3296 [CRITICAL] wpeverest everest_forms Deserialization of Untrusted Data
wpeverest everest_forms Deserialization of Untrusted Data
The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling PHP's native unserialize() on stored entry meta values without passing the allowed_classes parameter. This makes it possible for unauthenticated attackers to inject a serialized PHP object payload through any public Everest Forms form field. The payload survives sanitize_text_field() sanitization (serialization control characters are not stripped) and is stored in the wp_evf_entrymeta database table. When an administrator views entries or views an individual entry, the unsafe unseriali
No detection rules found.
Nuclei
Everest Forms WordPress Plugin <= 3.4.3 - PHP Object Injection
nuclei·CVSS 9.8
CVE-2026-3296 [CRITICAL] Everest Forms WordPress Plugin <= 3.4.3 - PHP Object Injection
Everest Forms WordPress Plugin <= 3.4.3 - PHP Object Injection
The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling PHP's native unserialize() on stored entry meta values without passing the allowed_classes parameter. This makes it possible for unauthenticated attackers to inject a serialized PHP object payload through any public Everest Forms form field. The payload survives sanitize_text_field() sanitization (serialization control characters are not stripped) and is stored in the wp_evf_entrymeta database table. When an administrator views entries or views an individual entry, the unsafe unse
https://plugins.trac.wordpress.org/browser/everest-forms/tags/3.4.3/includes/admin/views/html-admin-page-entries-view.php#L133https://plugins.trac.wordpress.org/browser/everest-forms/tags/3.4.3/includes/evf-core-functions.php#L5594https://plugins.trac.wordpress.org/browser/everest-forms/trunk/includes/admin/views/html-admin-page-entries-view.php#L133https://plugins.trac.wordpress.org/changeset/3489938/everest-forms/tags/3.4.4/readme.txt?old=3464753&old_path=everest-forms%2Ftags%2F3.4.3%2Freadme.txthttps://plugins.trac.wordpress.org/changeset?old_path=/everest-forms/tags/3.4.3&new_path=/everest-forms/tags/3.4.4https://www.wordfence.com/threat-intel/vulnerabilities/id/2693ae37-790d-4b18-a9ec-054c8c27b8bc?source=cve
2026-04-08
Published
Exploited in the wild