← WordPress Vulnerabilities
WordPress security by component

Everest Forms

Everest Forms is a WordPress component with 21 published CVE records in this archive. The latest tracked vulnerability was published Jul 09, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: everest-forms

CVE-2026-12270: Everest Forms: A security weakness

Everest Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is 3.4.2 to < 3.5.0.

PublishedJul 09, 2026
Known safe version3.5.0
Safe version
Jul 09, 2026 CVE-2026-12270
Everest Forms: A security weakness
Everest Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is 3.4.2 to < 3.5.0.
3.5.0
CVE6.5
NVDPending
Jul 09, 2026 CVE-2026-11571
Everest Forms: A security weakness
Everest Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 3.5.0.
3.5.0
CVE7.5
NVDPending
Jun 26, 2026 CVE-2026-57312
Everest Forms: Cross-site scripting
Everest Forms is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.4.8.
3.5.0
CVE7.1
NVDPending
May 28, 2026 CVE-2026-4888
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder: A security weakness
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.4.7.
> 3.4.7
CVE4.3
NVDPending
Apr 20, 2026 CVE-2026-5478
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder: Filesystem traversal
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 3.4.4.
> 3.4.4
CVE8.1
NVDPending
Apr 08, 2026 CVE-2026-3296
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder: Code execution
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 3.4.3.
> 3.4.3
CVE9.8
NVDPending
Mar 31, 2026 CVE-2026-3300
Everest Forms Pro: Code execution
Everest Forms Pro is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is <= 1.9.12.
> 1.9.12
CVE9.8
NVDPending
Feb 19, 2026 CVE-2026-22422
Everest Forms: Cross-site scripting
Everest Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.3
NVDPending
Jun 25, 2025 CVE-2025-5927
Everest Forms (Pro): Code execution
Everest Forms (Pro) is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.5
NVDPending
May 15, 2025 CVE-2024-8542
Everest Forms: Cross-site scripting
Everest Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Apr 11, 2025 CVE-2025-3439
Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for: Code execution
Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVDPending
Apr 11, 2025 CVE-2025-3422
The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for: A security weakness
The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD6.3
Apr 11, 2025 CVE-2025-3421
Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for: Cross-site scripting
Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Feb 25, 2025 CVE-2025-1128
Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for: Dangerous file upload
Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE9.8
NVDPending
Feb 13, 2025 CVE-2024-13125
Everest Forms: Cross-site scripting
Everest Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE3.5
NVDPending
Nov 26, 2024 CVE-2024-10471
Everest Forms: Cross-site scripting
Everest Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Jun 14, 2024 CVE-2023-51377
Everest Forms: A security weakness
Everest Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Apr 09, 2024 CVE-2024-1812
Everest Forms: Server-side request forgery
Everest Forms is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE7.2
NVDPending
Feb 01, 2024 CVE-2023-51695
Everest Forms – Build Contact Forms, Surveys, Polls, Application Forms, and more with Ease!: Cross-site scripting
Everest Forms – Build Contact Forms, Surveys, Polls, Application Forms, and more with Ease! is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Dec 21, 2021 CVE-2021-24907
Contact Form, Drag and Drop Form Builder for: Cross-site scripting
Contact Form, Drag and Drop Form Builder for is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jul 18, 2019 CVE-2019-13575
Everest Forms: SQL injection
Everest Forms is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8