📦 Everest Forms

by Wpeverest

🔍 What is Everest Forms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-3439

CRITICAL CVSS 9.8 Apr 11, 2025

The Everest Forms WordPress plugin is vulnerable to PHP object injection via deserialization of untrusted input in the 'field_value' parameter. This allows unauthenticated attackers to inject PHP obje...

CVE-2025-1128

CRITICAL CVSS 9.8 Feb 25, 2025

This vulnerability in the Everest Forms WordPress plugin allows unauthenticated attackers to upload, read, and delete arbitrary files on affected servers. It affects all versions up to 3.0.9.4 due to ...

CVE-2024-1812

HIGH CVSS 7.2 Apr 9, 2024

The Everest Forms WordPress plugin has a Server-Side Request Forgery (SSRF) vulnerability that allows unauthenticated attackers to make arbitrary web requests from the vulnerable server. This can be u...

CVE-2024-8542

MEDIUM CVSS 4.8 May 15, 2025

The Everest Forms WordPress plugin before version 3.0.3.1 contains a stored cross-site scripting (XSS) vulnerability in its settings. This allows authenticated administrators to inject malicious scrip...

CVE-2025-26841

MEDIUM CVSS 6.1 May 12, 2025

A Cross-Site Scripting (XSS) vulnerability in Everest Forms WordPress plugin before version 3.0.9 allows attackers to execute arbitrary JavaScript code via file upload functionality. This affects Word...

CVE-2025-3422

MEDIUM CVSS 5.4 Apr 11, 2025

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to execute arbitrary shortcodes through the Everest Forms plugin. Attackers can leverage this to perform ...