Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-62103: Everest Forms allows unauthenticated object injection

CVE-2026-62103 · published 16 days ago
Summary

The Everest Forms plugin for WordPress (versions up to 3.6.0) can be tricked into processing specially crafted data without any login. This could let an attacker run unwanted code on your site, potentially stealing data or taking control. Update the plugin to the latest version or remove it if you cannot apply the update.

What to do
  • Update wpeverest everest forms to version 3.6.1.
Affected software
VendorProductAffected versions
wpeverest everest forms <= 3.6.0
Fix: upgrade to 3.6.1
Original advisory text
Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.
Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published11 Sep 2026
Updated27 Sep 2026
First seen11 Sep 2026
Sources
CVE-2026-62103 · MITRE
Track software like this
Free during beta