CVE-2026-62103
A critical vulnerability allows attackers to inject PHP objects into the Everest Forms plugin without authentication. This flaw can lead to arbitrary code execution and compromise the entire site. The issue affects all versions up to and including 3.6.0.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Everest Forms WordPress plugin, versions 3.6.0 and earlier.
Real-world impact
An attacker could inject malicious PHP objects, enabling them to run arbitrary code on the server, steal data, or take full control of the affected website.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited over the network with no authentication or user interaction, and it can compromise confidentiality, integrity, and availability of the system.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources