Impact
The vulnerability is an unauthenticated PHP Object injection in Everest Forms plugin versions up to 3.6.0. Attackers can send specially crafted serialized objects to trigger arbitrary object creation and code execution, potentially allowing full compromise of the hosted WordPress site.
Affected Systems
WordPress sites that have the Everest Forms plugin installed with a version 3.6.0 or earlier are affected. Any instance of the plugin without the update to 3.6.1 or later remains vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating critical severity. The EPSS score is < 1%, but the lack of a C legitimate high exploitation risk, especially since the flaw is unauthenticated and can be triggered via crafted HTTP requests to the plugin’s endpoints. Remediation is urgent due to the simplicity of the injection payloads and the remote code execution potential.
OpenCVE Enrichment