WordPress security by component
Everest Forms
Plugin description
Everest Forms is a WordPress component with 21 published CVE records in this archive. The latest tracked vulnerability was published Jul 09, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
everest-formsLatest vulnerability
CVE-2026-12270: Everest Forms: A security weakness
Everest Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is 3.4.2 to < 3.5.0.
| Safe version |
|
||
|---|---|---|---|
| Jul 09, 2026 |
CVE-2026-12270
Everest Forms: A security weakness
Everest Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is 3.4.2 to < 3.5.0.
|
3.5.0 |
CVE6.5
NVDPending
|
| Jul 09, 2026 |
CVE-2026-11571
Everest Forms: A security weakness
Everest Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.5.0.
|
3.5.0 |
CVE7.5
NVDPending
|
| Jun 26, 2026 |
CVE-2026-57312
Everest Forms: Cross-site scripting
Everest Forms is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.4.8.
|
3.5.0 |
CVE7.1
NVDPending
|
| May 28, 2026 |
CVE-2026-4888
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder: A security weakness
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.4.7.
|
> 3.4.7 |
CVE4.3
NVDPending
|
| Apr 20, 2026 |
CVE-2026-5478
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder: Filesystem traversal
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 3.4.4.
|
> 3.4.4 |
CVE8.1
NVDPending
|
| Apr 08, 2026 |
CVE-2026-3296
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder: Code execution
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 3.4.3.
|
> 3.4.3 |
CVE9.8
NVDPending
|
| Mar 31, 2026 |
CVE-2026-3300
Everest Forms Pro: Code execution
Everest Forms Pro is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 1.9.12.
|
> 1.9.12 |
CVE9.8
NVDPending
|
| Feb 19, 2026 |
CVE-2026-22422
Everest Forms: Cross-site scripting
Everest Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jun 25, 2025 |
CVE-2025-5927
Everest Forms (Pro): Code execution
Everest Forms (Pro) is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.5
NVDPending
|
| May 15, 2025 |
CVE-2024-8542
Everest Forms: Cross-site scripting
Everest Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Apr 11, 2025 |
CVE-2025-3439
Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for: Code execution
Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Apr 11, 2025 |
CVE-2025-3422
The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for: A security weakness
The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVD6.3
|
| Apr 11, 2025 |
CVE-2025-3421
Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for: Cross-site scripting
Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Feb 25, 2025 |
CVE-2025-1128
Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for: Dangerous file upload
Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Feb 13, 2025 |
CVE-2024-13125
Everest Forms: Cross-site scripting
Everest Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE3.5
NVDPending
|
| Nov 26, 2024 |
CVE-2024-10471
Everest Forms: Cross-site scripting
Everest Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Jun 14, 2024 |
CVE-2023-51377
Everest Forms: A security weakness
Everest Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Apr 09, 2024 |
CVE-2024-1812
Everest Forms: Server-side request forgery
Everest Forms is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Feb 01, 2024 |
CVE-2023-51695
Everest Forms – Build Contact Forms, Surveys, Polls, Application Forms, and more with Ease!: Cross-site scripting
Everest Forms – Build Contact Forms, Surveys, Polls, Application Forms, and more with Ease! is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Dec 21, 2021 |
CVE-2021-24907
Contact Form, Drag and Drop Form Builder for: Cross-site scripting
Contact Form, Drag and Drop Form Builder for is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Jul 18, 2019 |
CVE-2019-13575
Everest Forms: SQL injection
Everest Forms is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|