CRITICAL
9.8 CVE-2026-62103 Published 11 Sept 2026
Everest Forms PHP Object Injection
Worried this affects one of your servers?
Unauthenticated PHP Object Injection found in Everest Forms plugin versions 3.6.0 and earlier.
An attacker could exploit this vulnerability to inject malicious PHP objects, leading to remote code execution.
Reference: CVE-2026-62103 on NVD
← Back to Security News