CVE-2026-3296Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling PHP's native unserialize() on stored entry meta values without passing the allowed_classes parameter. This makes it possible for unauthenticated attackers to inject a serialized PHP object payload through any public Everest Forms form field. The payload survives sanitize_text_field() sanitization (serialization control characters are not stripped) and is stored in the wp_evf_entrymeta database table. When an administrator views entries or views an individual entry, the unsafe unserialize() call processes the stored data without class restrictions.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 13 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 10 signals
  • Disclosure: 9 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 6 mentions (2026-04-08); latest day: 1
  • 13 total mentions across 5 days

Deep dive

Activity timeline13 mentions / 5d
02356Mentions · 2026-04-08: 6Mentions · 2026-05-12: 1Mentions · 2026-05-18: 1Mentions · 2026-06-15: 4Mentions · 2026-07-21: 1PoC Mentioned / Linked · 2026-04-08: 1PoC Mentioned / Linked · 2026-05-18: 1Patch / Workaround · 2026-04-08: 1Technical Details · 2026-04-08: 5Technical Details · 2026-05-12: 1Technical Details · 2026-05-18: 1Technical Details · 2026-06-15: 2Technical Details · 2026-07-21: 104-0805-1205-1806-1507-21
Signal classification3 categories
Disclosure
969.2%
General
323.1%
Patch
17.7%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-04-086
Disclosure5Patch1
2026-05-121
General1
2026-05-181
Disclosure1
2026-06-154
Disclosure2General2
2026-07-211
Disclosure1
Full discourse13 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-3296 - critical 🚨 Everest Forms WordPress Plugin <= 3.4.3 - PHP Object Injection > The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all v... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-3296 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE-2026-3296, a PHP Object Injection flaw in Everest Forms WordPress plugin up to version 3.4.3, and provides a link to further information without detailing exploits or patches.

    012039192.0K
    1.3K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-3296 · 5.2 → 9.8 CVE-2026-3296: Critical WordPress RCE in Everest Forms Plugin

    Post summary

    The text announces a critical RCE vulnerability in the Everest Forms WordPress plugin, but provides no evidence of proof‑of‑concept, exploitation, or patches.

    1001035
    267 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Status: QUEUED FOR http://RESEARCH.LYRIE.AI Priority: CRITICAL Date Published: May 3, 2026 CVE ID: CVE-2026-3296 CVE-2026-3296: Critical WordPress RCE in Everest Forms Plugin

    Post summary

    A critical WordPress remote code execution vulnerability (CVE‑2026‑3296) in the Everest Forms plugin has been disclosed.

    1001031
    267 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2026-3296、CVSS 9.8 (Critical) Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry Metadata https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/everest-forms/everest-forms-343-unauthenticated-php-object-injection-via-form-entry-metadata

    Post summary

    Wordfence reports CVE-2026-3296 as a critical unauthenticated PHP Object Injection in Everest Forms <=3.4.3, providing technical details but no evidence of active exploitation, PoC, or patch.

    00011532
    6.8K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-3296: Critical WordPress RCE in Everest Forms Plugin Status: QUEUED FOR http://RESEARCH.LYRIE.AI Priority: CRITICAL Date Published: May 3, 2026 CVE ID: CVE-2026-3296

    Post summary

    A new critical WordPress RCE (CVE‑2026‑3296) affecting the Everest Forms plugin has been announced and queued for research, with no PoC, exploit, patch, or evidence of active exploitation disclosed.

    1000029
    267 followersView on X
  • Dr. Siraj Dokadia@SirajD_Official
    Disclosure

    CVE-2026-3296 - Everest Forms WordPress Plugin RCE vulnerability https://dy.si/ddv6Z https://t.co/jv78dnwawL

    Post summary

    CVE-2026-3296 is disclosed as a remote code execution flaw in the Everest Forms WordPress plugin. The provided links likely lead to additional information or a PoC, but no exploitation details or patches are mentioned.

    0001068
    17 followersView on X
  • Threat Intelligence@threatintel
    General

    #ThreatProtection #CVE-2026-3296 - Everest Forms WordPress Plugin #RCE #vulnerability, read more about Symantec's protection: https://www.broadcom.com/support/security-center/protection-bulletin/cve-2026-3296-everest-forms-wordpress-plugin-rce-vulnerability

    Post summary

    The tweet alerts on CVE‑2026‑3296, an RCE issue in the Everest Forms WordPress plugin, and links to a Symantec protection bulletin, but it provides no PoC, exploit code, or active exploitation evidence.

    010001.1K
    115.1K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-3296 — CVSS 9.8/10 ██████████ The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/rBj32BFdan

    Post summary

    The tweet warns of a critical CVE‑2026‑3296 affecting Everest Forms WP plugin, a PHP Object Injection flaw with CVSS 9.8/10, and urges users to apply the available patch.

    1000054
    16 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-3296-wordpress-rce #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The reference only points to a URL and includes hashtags; key details about the CVE or its exploitation are not explicitly stated.

    0000025
    267 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3296 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3296 #CVE-2026-3296 #CVE #Critical #Wordpress #CyberSecurity #InfoSec https://t.co/G54faajOAc

    Post summary

    The tweet discloses CVE-2026-3296 as a critical WordPress vulnerability with a severity score of 9.8, but offers no additional technical, exploit, or mitigation details.

    0000042
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3296 The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from for… https://www.cve.org/CVERecord?id=CVE-2026-3296

    Post summary

    Everest Forms plugin (≤3.4.3) is susceptible to PHP Object Injection through deserialization of untrusted input, as outlined in CVE-2026-3296; no PoC, exploit code, active exploitation, or patch is referenced.

    0000079
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3296: CRITICAL] WordPress Everest Forms plugin up to version 3.4.3 is vulnerable to PHP Object Injection through untrusted input, enabling attackers to inject malicious payloads into the database.#cve,CVE-2026-3296,#cybersecurity https://cvefind.com/CVE-2026-3296

    Post summary

    The post discloses a critical PHP Object Injection flaw in the WordPress Everest Forms plugin (v≤3.4.3) that permits injection of malicious payloads into the database.

    0000040
    619 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-3296: Everest Forms &lt;= 3.4.3 - Unauthen... Unauthenticated RCE via unserialize() with no class restrictions - drop payload in any form field, wait for admin to vie... https://zerodaysignal.com/vulnerability/CVE-2026-3296 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-3296 is an unauthenticated remote code execution flaw in Everest Forms up to 3.4.3, exploitable via unserialize() without class restrictions; no patch or active exploitation is reported.

    0000053
    204 followersView on X

Explore more