Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-62103: Everest Forms allows unauthenticated object injection
CVE-2026-62103 · published 16 days ago
Summary
The Everest Forms plugin for WordPress (versions up to 3.6.0) can be tricked into processing specially crafted data without any login. This could let an attacker run unwanted code on your site, potentially stealing data or taking control. Update the plugin to the latest version or remove it if you cannot apply the update.
What to do
- Update wpeverest everest forms to version 3.6.1.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| wpeverest | everest forms |
<= 3.6.0 Fix: upgrade to 3.6.1
|
Original advisory text
Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.
Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.
Severity
9.8
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published11 Sep 2026
Updated27 Sep 2026
First seen11 Sep 2026
Track software like this
Free during beta