OVERVIEW CVE-2026-3296 is a PHP Object Injection vulnerability affecting the Everest Forms plugin for WordPress in all versions up to and including 3.4.3. The flaw exists in the html-admin-page-entries-view.php file, which improperly deserializes untrusted user input from form entry metadata without restricting allowed PHP classes. Attackers can inject malicious serialized objects through public form fields, which persist in the database and are later processed by administrators. SEVERITY This vulnerability carries a critical CVSS 3.1 score of 9.8, with a network-based attack vector requiring no authentication, low attack complexity, and no user interaction. The exploitation results in high impact across confidentiality, integrity, and availability. The attack surface is extensive, as any unauthenticated user can submit a form containing a malicious payload. The serialized payload successfully bypasses the sanitize_text_field() function, making exploitation straightforward from a technical perspective. EXPLOITATION STATUS Current exploitation activity appears minimal. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog and is inactive on threat intelligence hot lists. The EPSS score of 0.00026 indicates this CVE ranks higher than approximately 0.07% of all published vulnerabilities in terms of predicted exploitation probability. No evidence suggests public exploit code availability or widespread community attention at this time, though organizations running vulnerable versions should apply patches immediately given the critical severity rating.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Wpeverest | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder | >= 0, <= 3.4.3CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.