All verified exploits

CVE-2026-3296 PHP Object Injection via Everest Forms Unserialize

Deterministic critical WordPress Added cve-verified-cve-2026-3296

Detects WordPress instances with Everest Forms ≤ 3.4.3 installed, where the plugin calls PHP's native unserialize() on stored form entry metadata in html-admin-page-entries-view.php without passing the allowed_classes parameter. An unauthenticated attacker can submit a serialized PHP object payload via any public form field — it survives sanitize_text_field() sanitization and is stored in wp_evf_entrymeta. When an administrator views entries, the unsafe unserialize() call processes the stored data without class restrictions, enabling POP chain exploitation for file write, SSRF, or remote code execution. Update Everest Forms to 3.4.4 or later.

Related WordPress exploits

Is your app exploitable through CVE-2026-3296?

Scan your domain free