CVE-2025-52709: WordPress Everest Forms plugin <= 3.2.2 - PHP Object Injection Vulnerability
Published Jun 27, 2025
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
WPEverest Everest Forms>=n/a, <=3.2.2
Remediation
Information
Update the WordPress Everest Forms plugin to the latest available version (at least 3.2.3).
Event History
Jun 27, 2025
CVE Published
via MITRE·11:52 AM
Rejected
via MITRE·11:52 AM
Data Sourced
via NVD·12:15 PM
Description
Sep 4, 2025
Rejected
via MITRE·02:49 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-52709?
CVE-2025-52709 is classified as a medium-severity vulnerability due to its potential for object injection.
2
How do I fix CVE-2025-52709?
To fix CVE-2025-52709, update the Everest Forms plugin to version 3.2.3 or later.
3
What impact does CVE-2025-52709 have on my site?
CVE-2025-52709 could allow attackers to exploit object injection vulnerabilities, potentially leading to remote code execution.
4
Which versions of Everest Forms are affected by CVE-2025-52709?
CVE-2025-52709 affects Everest Forms versions up to and including 3.2.2.
5
Is CVE-2025-52709 exploitable without authentication?
Yes, CVE-2025-52709 can be exploited without authentication, making it more critical for site security.