Junglewise Threat Intelligence

CVE-2026-62103: Everest Forms PHP Object Injection

CVE-2026-62103 · Severity: critical · CVSS 9.8 · Published 2026-09-11

Technologies: Everest Forms.

Executive brief

Everest Forms is a popular WordPress plugin for creating contact and form submission pages. An unauthenticated attacker can exploit a PHP object injection flaw to execute arbitrary code on affected WordPress sites, leading to complete server compromise, data theft, and malware installation.

Technical details

A PHP Object Injection vulnerability exists in Everest Forms versions up to 3.6.0, exploitable without authentication. The vulnerability allows attackers to manipulate object serialization/deserialization to achieve remote code execution on the affected server. The attack requires only network access to the affected WordPress installation; no user interaction or valid credentials are needed. Successful exploitation enables an attacker to run arbitrary PHP code with the privileges of the web server process. The vulnerability was patched in version 3.6.1 released on September 11, 2026.

Affected products

  • Everest Forms Everest Forms 3.6.0 and earlier

Timeline

  • 2026-09-11: disclosed: Vulnerability disclosed and patched in version 3.6.1
  • 2026-09-11: advisory: CVE-2026-62103 published
  • 2026-08-30: other: Vulnerability initially reported to Patchstack by LueRader

References