Detects WordPress instances with Everest Forms ≤ 3.4.3 installed, where the plugin calls PHP's native unserialize() on stored form entry metadata in html-admin-page-entries-view.php without passing the allowed_classes parameter. An unauthenticated attacker can submit a serialized PHP object payload via any public form field — it survives sanitize_text_field() sanitization and is stored in wp_evf_entrymeta. When an administrator views entries, the unsafe unserialize() call processes the stored data without class restrictions, enabling POP chain exploitation for file write, SSRF, or remote code execution. Update Everest Forms to 3.4.4 or later.
Is your app exploitable through CVE-2026-3296?
Scan your domain free