Wpeverest

Everest Forms

24 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 11.09.2026 18:12:03
  • Zuletzt bearbeitet 11.09.2026 21:17:11

Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.

  • EPSS 0.3%
  • Veröffentlicht 28.08.2026 11:29:29
  • Zuletzt bearbeitet 28.08.2026 20:19:02

The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the `load_previous_field_value()` method in `class-evf-form-task.php` accepting arbitrary URL values from ...

  • EPSS 0.35%
  • Veröffentlicht 16.08.2026 04:24:54
  • Zuletzt bearbeitet 20.08.2026 12:48:10

The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.2. This is due to the plugin not properly verifying that a...

  • EPSS 0.23%
  • Veröffentlicht 26.06.2026 14:52:55
  • Zuletzt bearbeitet 26.06.2026 16:16:34

Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions.

  • EPSS 0.28%
  • Veröffentlicht 27.05.2026 23:26:34
  • Zuletzt bearbeitet 28.05.2026 13:45:25

The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and includi...

  • EPSS 1.02%
  • Veröffentlicht 20.04.2026 19:27:08
  • Zuletzt bearbeitet 22.04.2026 20:22:50

The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3.4.4. This is due to the plugin trusting attacker-controlled old_files data from public form submissions as legitimate ser...

  • EPSS 3.47%
  • Veröffentlicht 08.04.2026 01:24:43
  • Zuletzt bearbeitet 25.07.2026 10:10:00

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling...

  • EPSS 0.22%
  • Veröffentlicht 19.02.2026 08:26:48
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in wpeverest Everest Forms everest-forms allows Code Injection.This issue affects Everest Forms: from n/a through <= 3.4.1.

  • EPSS 0.28%
  • Veröffentlicht 05.11.2025 02:25:52
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.7 via deserialization of untrusted input in the mime_content_type() function. This makes it possible for unauthenticated atta...

  • EPSS 0.06%
  • Veröffentlicht 27.06.2025 11:52:29
  • Zuletzt bearbeitet 04.09.2025 10:42:31

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.