CVE-2026-62103: WordPress Everest Forms plugin <= 3.6.0 - PHP Object Injection vulnerability
Published Sep 11, 2026
·Updated
Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.
Affected Software
1 affected component
WordPress Everest Forms<=3.6.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Everest Forms pluginto a version that resolves this vulnerability.Fixed in 3.6.1
Event History
Sep 11, 2026
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or prior access to the site. The supplied vector indicates it can be reached over the network.
2
Which installations are affected?
WordPress sites using Everest Forms version 3.6.0 or earlier are affected according to the available information.
3
What is the potential impact?
The listed severity vector rates confidentiality, integrity, and availability impact as high. Successful exploitation could therefore have serious consequences for the affected WordPress site and its data.