logo

100,000+ Sites Exposed: Critical 9.8 CVSS Flaw Hits Everest Forms WordPress Plugin

ID: 34083ffc-bfca-5f76-81e3-30770b5ed550

STIX ID: report--34083ffc-bfca-5f76-81e3-30770b5ed550

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-04-09

Date Updated: 2026-04-23

Author: Ddos

...
...

Everest Forms (<= 3.4.3) contains a critical unauthenticated PHP Object Injection (CVE-2026-3296, CVSS 9.8) caused by unsafe unserialize() usage on stored form metadata; an attacker can submit a serialized payload through public forms, persist it in wp_evf_entrymeta, and trigger code execution when an administrator views entries — version 3.4.4 fixes the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.