CVE-2025-8871 describes a PHP Object Injection vulnerability in the Everest Forms (Pro) WordPress plugin, affecting all versions up to and including 1.9.7. This medium-severity vulnerability (CVSS 5.6) allows unauthenticated attackers to inject PHP objects through deserialization in the mime_content_type() function, provided specific form fields are present and the PHP version is prior to 8. While no known POP chain exists within the plugin itself, exploitation could lead to data compromise, file deletion, or code execution if another plugin or theme introduces a POP chain. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| WPEverest | Everest Forms Pro | >= 0, <= 1.9.7CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.