Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-3296

50
FAUCET Score

OVERVIEW CVE-2026-3296 is a PHP Object Injection vulnerability affecting the Everest Forms plugin for WordPress in all versions up to and including 3.4.3. The flaw exists in the html-admin-page-entries-view.php file, which improperly deserializes untrusted user input from form entry metadata without restricting allowed PHP classes. Attackers can inject malicious serialized objects through public form fields, which persist in the database and are later processed by administrators. SEVERITY This vulnerability carries a critical CVSS 3.1 score of 9.8, with a network-based attack vector requiring no authentication, low attack complexity, and no user interaction. The exploitation results in high impact across confidentiality, integrity, and availability. The attack surface is extensive, as any unauthenticated user can submit a form containing a malicious payload. The serialized payload successfully bypasses the sanitize_text_field() function, making exploitation straightforward from a technical perspective. EXPLOITATION STATUS Current exploitation activity appears minimal. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog and is inactive on threat intelligence hot lists. The EPSS score of 0.00026 indicates this CVE ranks higher than approximately 0.07% of all published vulnerabilities in terms of predicted exploitation probability. No evidence suggests public exploit code availability or widespread community attention at this time, though organizations running vulnerable versions should apply patches immediately given the critical severity rating.

Impacted Technologies

VendorProductVersion(s)CPE
WpeverestEverest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder
>= 0, <= 3.4.3CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.47%
Probability of exploitation in next 30 days
EPSS Percentile
87.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0347 is in the 80th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

plugins.trac.wordpress.org / browser/everest-forms/tags/3.4.3/includes/admin/views/html-admin-page-entries-view.php
plugins.trac.wordpress.org / browser/everest-forms/tags/3.4.3/includes/evf-core-functions.php
plugins.trac.wordpress.org / browser/everest-forms/trunk/includes/admin/views/html-admin-page-entries-view.php
plugins.trac.wordpress.org / changeset/3489938/everest-forms/tags/3.4.4/readme.txt
plugins.trac.wordpress.org / changeset
wordfence.com / threat-intel/vulnerabilities/id/2693ae37-790d-4b18-a9ec-054c8c27b8bc