Executive brief
Everest Forms, a popular WordPress plugin used for creating contact and payment forms, contains a critical security flaw. An attacker can submit malicious data through any public form on a website, which is then stored in the site's database. When a site administrator later views these form submissions, the malicious data is automatically processed, potentially allowing the attacker to take full control of the website or delete sensitive information.
Technical details
The Everest Forms plugin is vulnerable to PHP Object Injection via the 'unserialize()' function in the 'html-admin-page-entries-view.php' file. The vulnerability occurs because the plugin fails to use the 'allowed_classes' parameter when deserializing stored entry metadata. An unauthenticated attacker can submit a serialized PHP object through any public form field; this payload bypasses 'sanitize_text_field()' because serialization control characters are not stripped. The payload is stored in the 'wp_evf_entrymeta' table and is executed when an administrator views the entries in the WordPress dashboard. If a suitable POP chain is present on the server, this can lead to remote code execution or arbitrary file deletion. The issue is fixed in version 3.4.4.
Affected products
- WPEverest Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder up to, and including, 3.4.3
Timeline
- 2026-04-08: disclosed: Initial publication of the vulnerability advisory.
- 2026-04-08: advisory: Wordfence published detailed vulnerability information.
References
- https://plugins.trac.wordpress.org/browser/everest-forms/tags/3.4.3/includes/admin/views/html-admin-page-entries-view.php
- https://plugins.trac.wordpress.org/browser/everest-forms/tags/3.4.3/includes/evf-core-functions.php
- https://plugins.trac.wordpress.org/browser/everest-forms/trunk/includes/admin/views/html-admin-page-entries-view.php
- https://plugins.trac.wordpress.org/changeset/3489938/everest-forms/tags/3.4.4/readme.txt?old=3464753&old_path=everest-forms%2Ftags%2F3.4.3%2Freadme.txt
- https://plugins.trac.wordpress.org/changeset?old_path=/everest-forms/tags/3.4.3&new_path=/everest-forms/tags/3.4.4
- https://www.wordfence.com/threat-intel/vulnerabilities/id/2693ae37-790d-4b18-a9ec-054c8c27b8bc?source=cve