WordPress security by component
Everest Forms
Plugin description
Everest Forms builds customizable WordPress forms with a drag-and-drop editor, reusable fields, submissions, and form management tools.
Everest Forms (everest-forms) is a WordPress plugin with 24 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
everest-formsLatest vulnerability
CVE-2026-62103: Everest Forms permits unauthenticated PHP object injection
Everest Forms through 3.6.0 permits PHP object injection without authentication. The CNA vector requires no privileges or user interaction and rates confidentiality, integrity, and availability impact as high. The authoritative export does not identify the endpoint, parameter, deserialization operation, usable gadget chain, or the exact post-injection effect.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-62103
Everest Forms permits unauthenticated PHP object injection
Everest Forms through 3.6.0 permits PHP object injection without authentication. The CNA vector requires no privileges or user interaction and rates confidentiality, integrity, and availability impact as high. The authoritative export does not identify the endpoint, parameter, deserialization operation, usable gadget chain, or the exact post-injection effect.
|
3.6.1 |
CVE9.8
NVDPending
|
| Aug 28, 2026 |
CVE-2026-5096
Everest Forms upload values permit unauthenticated SSRF
Everest Forms through 3.4.4 accepts an arbitrary upload-field URL from POST data in load_previous_field_value(). When another required field is left empty and the form rerenders, get_local_file_size() passes that URL to wp_remote_head(), allowing an unauthenticated attacker to make the WordPress server send HTTP HEAD requests to arbitrary destinations.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Aug 16, 2026 |
CVE-2026-13167
Everest Forms delegated access permits unauthorized plugin activation
Everest Forms through 3.5.2 exposes an activation operation to users with delegated Everest Forms management capabilities without also requiring WordPress's activate_plugins capability. A user who can reach the affected Everest Forms administration page can obtain its nonce and activate any plugin that is already installed.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jul 09, 2026 |
CVE-2026-12270
Everest Forms: A security weakness
Everest Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is 3.4.2 to < 3.5.0.
|
3.5.0 |
CVE6.5
NVDPending
|
| Jul 09, 2026 |
CVE-2026-11571
Everest Forms: A security weakness
Everest Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.5.0.
|
3.5.0 |
CVE7.5
NVDPending
|
| Jun 26, 2026 |
CVE-2026-57312
Everest Forms: Cross-site scripting
Everest Forms is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.4.8.
|
3.5.0 |
CVE7.1
NVDPending
|
| May 28, 2026 |
CVE-2026-4888
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder: A security weakness
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.4.7.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Apr 20, 2026 |
CVE-2026-5478
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder: Filesystem traversal
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 3.4.4.
|
See mitigation notes |
CVE8.1
NVDPending
|
| Apr 08, 2026 |
CVE-2026-3296
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder: Code execution
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 3.4.3.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Mar 31, 2026 |
CVE-2026-3300
Everest Forms Pro: Code execution
Everest Forms Pro is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 1.9.12.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Feb 19, 2026 |
CVE-2026-22422
Everest Forms: Cross-site scripting
Everest Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jun 25, 2025 |
CVE-2025-5927
Everest Forms (Pro): Code execution
Everest Forms (Pro) is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.5
NVDPending
|
| May 15, 2025 |
CVE-2024-8542
Everest Forms: Cross-site scripting
Everest Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Apr 11, 2025 |
CVE-2025-3439
Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for: Code execution
Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Apr 11, 2025 |
CVE-2025-3422
The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for: A security weakness
The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVD6.3
|
| Apr 11, 2025 |
CVE-2025-3421
Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for: Cross-site scripting
Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Feb 25, 2025 |
CVE-2025-1128
Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for: Dangerous file upload
Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Feb 13, 2025 |
CVE-2024-13125
Everest Forms: Cross-site scripting
Everest Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE3.5
NVDPending
|
| Nov 26, 2024 |
CVE-2024-10471
Everest Forms: Cross-site scripting
Everest Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Jun 14, 2024 |
CVE-2023-51377
Everest Forms: A security weakness
Everest Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Apr 09, 2024 |
CVE-2024-1812
Everest Forms: Server-side request forgery
Everest Forms is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Feb 01, 2024 |
CVE-2023-51695
Everest Forms – Build Contact Forms, Surveys, Polls, Application Forms, and more with Ease!: Cross-site scripting
Everest Forms – Build Contact Forms, Surveys, Polls, Application Forms, and more with Ease! is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Dec 21, 2021 |
CVE-2021-24907
Contact Form, Drag and Drop Form Builder for: Cross-site scripting
Contact Form, Drag and Drop Form Builder for is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Jul 18, 2019 |
CVE-2019-13575
Everest Forms: SQL injection
Everest Forms is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD9.8
|