9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
CVE-2026-3296 CVE-2026-3296 is a CVSS 9.8 Critical unauthenticated PHP Object Injection vulnerability in the Everest Forms WordPress plugin CVE-2026-3296 — Everest Forms PHP Object Injection Scanner Plugin: Everest Forms – Contact Form, Payment Form,...
Basic Information
ID
C456B1B4-9CA6-51F5-8F33-3147A7C9DC79
Published
May 26, 2026 at 06:33
Modified
May 26, 2026 at 06:39