plugin

Everest Forms Vulnerabilities

36 known security issues reported for the Everest Forms WordPress plugin. Most recent disclosed Aug 27, 2026.

4 critical 2 high 15 medium

Running Everest Forms on your site? Check whether your installed version is affected.

Scan your site free

Everest Forms <= 3.4.4 - Unauthenticated Server-Side Request Forgery via Upload Field 'Previous Value'

medium

The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the `load_previous_field_value()` method in `class-evf-form-task.php` accepting arbitrary URL values from `$_POST` data for upload fields without domain restriction, which are...

CVSS:
5.3
Affected:
up to 3.4.4
Fixed in:
3.4.5
Disclosed:
Aug 27, 2026

CVE-2026-5096 on NVD →

Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI <= 3.5.2 - Missing Authorization to Authenticated (Delegated+) Arbitrary Plugin Activation via REST API and AJAX Endpoints

medium

The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for a...

CVSS:
4.3
Affected:
up to 3.5.2
Fixed in:
3.5.3
Disclosed:
Aug 15, 2026

CVE-2026-13167 on NVD →

Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI <= 3.4.8 - Reflected Cross-Site Scripting

medium

The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje...

CVSS:
6.1
Affected:
up to 3.4.8
Fixed in:
3.5.0
Disclosed:
Jun 25, 2026

CVE-2026-57312 on NVD →

Everest Forms <= 3.4.0 - Unauthenticated Missing Authorization

medium

The Everest Forms plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 3.4.0. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.4.0
Fixed in:
3.5.0
Disclosed:
Jun 18, 2026

CVE-2026-12270 on NVD →

Everest Forms <= 3.4.0 - Unauthenticated Information Exposure

medium

The Everest Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.4.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 3.4.0
Fixed in:
3.5.0
Disclosed:
Jun 18, 2026

CVE-2026-11571 on NVD →

Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder <= 3.4.7 - Missing Authorization to Authenticated (Subscriber+) Email Sending

medium

The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 3.4.7. This makes it possible for authenticated attackers, with Su...

CVSS:
4.3
Affected:
up to 3.4.7
Fixed in:
3.4.8
Disclosed:
May 27, 2026

CVE-2026-4888 on NVD →

Everest Forms <= 3.4.4 - Unauthenticated Arbitrary File Read and Deletion via Upload Field 'old_files' Parameter

high

The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3.4.4. This is due to the plugin trusting attacker-controlled old_files data from public form submissions as legitimate server-side upload state, and converting attacker-supplied URLs into loca...

CVSS:
8.1
Affected:
up to 3.4.4
Fixed in:
3.4.5
Disclosed:
Apr 20, 2026

CVE-2026-5478 on NVD →

Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry Metadata

critical

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling PHP's native unserialize() on stored entry meta values without passin...

CVSS:
9.8
Affected:
up to 3.4.3
Fixed in:
3.4.4
Disclosed:
Apr 7, 2026

CVE-2026-3296 on NVD →

Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder [everest-forms] <= 3.4.1 (unfixed)

unknown

[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in wpeverest Everest Forms everest-forms allows Code Injection.This issue affects Everest Forms: from n/a through <= 3.4.1.

Affected:
up to 3.4.1
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-22422 on NVD →

Everest Forms <= 3.4.1 - Unauthenticated Arbitrary Shortcode Execution

medium

The The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.4.1. This is due to the software allowing users to execute an action that does not properly validate a value before running d...

CVSS:
6.5
Affected:
up to 3.4.1
Fixed in:
3.4.2
Disclosed:
Sep 26, 2025

CVE-2026-22422 on NVD →

Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder [everest-forms] < 3.2.3

unknown
Affected:
up to 3.2.3
Fixed in:
3.2.3
Disclosed:
Jun 27, 2025

CVE-2025-52709 on NVD →

Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder [everest-forms] < 3.0.9

unknown

[en] Cross Site Scripting vulnerability in WPEVEREST Everest Forms before 3.0.9 allows an attacker to execute arbitrary code via a file upload.

Affected:
up to 3.0.9
Fixed in:
3.0.9
Disclosed:
May 12, 2025

CVE-2025-26841 on NVD →

Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.1.1 - Unauthenticated PHP Object Injection

critical

The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.1 via deserialization of untrusted input from the 'field_value' parameter. This makes it possible for unauthenticated attac...

CVSS:
9.8
Affected:
up to 3.1.1
Fixed in:
3.1.2
Disclosed:
Apr 10, 2025

CVE-2025-3439 on NVD →

Everest Forms <= 3.1.1 - Reflected Cross-Site Scripting

medium

The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'form_id' parameter in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible...

CVSS:
6.1
Affected:
up to 3.1.1
Fixed in:
3.1.2
Disclosed:
Apr 10, 2025

CVE-2025-3421 on NVD →

Everest Forms <= 3.1.1 - Authenticated (Subscriber+) Arbitrary Shortcode Execution

medium

The The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.1.1. This is due to the software allowing users to execute an action that does not properly validate a value bef...

CVSS:
5.4
Affected:
up to 3.1.1
Fixed in:
3.1.2
Disclosed:
Apr 10, 2025

CVE-2025-3422 on NVD →

Everest Forms <= 3.0.9.4 - Unauthenticated Arbitrary File Upload, Read, and Deletion

critical

The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due to missing file type and path validation in the 'format' method of the EVF_Form_Fields_Upload class in all versions up to, and including, 3...

CVSS:
9.8
Affected:
up to 3.0.9.4
Fixed in:
3.0.9.5
Disclosed:
Feb 17, 2025

CVE-2025-1128 on NVD →

Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder [everest-forms] < 3.0.8.1

unknown

[en] The Everest Forms WordPress plugin before 3.0.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 3.0.8.1
Fixed in:
3.0.8.1
Disclosed:
Feb 13, 2025

CVE-2024-13125 on NVD →

Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.0.8 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authent...

CVSS:
4.4
Affected:
up to 3.0.8
Fixed in:
3.0.8.1
Disclosed:
Jan 17, 2025

CVE-2024-13125 on NVD →

Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder [everest-forms] < 3.0.4.2

unknown

[en] The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 3.0.4.2
Fixed in:
3.0.4.2
Disclosed:
Nov 26, 2024

CVE-2024-10471 on NVD →

Everest Forms <= 3.0.4.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Everest Forms – Build Contact Forms, Surveys, Polls, Quizzes, Newsletter & Application Forms, and Many More with Ease! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.4.1 due to insufficient input sanitization and output escaping. This m...

CVSS:
4.4
Affected:
up to 3.0.4.1
Fixed in:
3.0.4.2
Disclosed:
Nov 5, 2024

CVE-2024-10471 on NVD →

Everest Forms <= 3.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Everest Forms – Build Contact Forms, Surveys, Polls, Quizzes, Newsletter & Application Forms, and Many More with Ease! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This mak...

CVSS:
4.4
Affected:
up to 3.0.3
Fixed in:
3.0.3.1
Disclosed:
Aug 1, 2024

CVE-2024-8542 on NVD →

Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder [everest-forms] < 2.0.3.1

unknown

[en] Missing Authorization vulnerability in WPEverest Everest Forms.This issue affects Everest Forms: from n/a through 2.0.3.

Affected:
up to 2.0.3.1
Fixed in:
2.0.3.1
Disclosed:
Jun 14, 2024

CVE-2023-51377 on NVD →

Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder [everest-forms] < 2.0.8

unknown

[en] The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to quer...

Affected:
up to 2.0.8
Fixed in:
2.0.8
Disclosed:
Apr 9, 2024

CVE-2024-1812 on NVD →

Everest Forms <= 2.0.7 - Unauthenticated Server-Side Request Forgery via font_url

high

The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and...

CVSS:
7.2
Affected:
up to 2.0.7
Fixed in:
2.0.8
Disclosed:
Mar 15, 2024

CVE-2024-1812 on NVD →

Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder [everest-forms] < 2.0.5

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Everest Forms – Build Contact Forms, Surveys, Polls, Application Forms, and more with Ease! allows Stored XSS.This issue affects Everest Forms – Build Contact Forms, Surveys, Polls, Application Forms, an...

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Feb 1, 2024

CVE-2023-51695 on NVD →

Everest Forms <= 2.0.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Everest Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.0.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject a...

CVSS:
4.4
Affected:
up to 2.0.4.1
Fixed in:
2.0.5
Disclosed:
Dec 27, 2023

CVE-2023-51695 on NVD →

Everest Forms <= 2.0.3 - Unauthorized Form Submission via Disabled Forms

medium

The Everest Forms plugin for WordPress is vulnerable to unauthorized form submission due to a missing validation check in the do_task function in versions up to, and including, 2.0.3. This makes it possible for unauthenticated attackers to submit disabled forms.

CVSS:
5.3
Affected:
up to 2.0.3
Fixed in:
2.0.3.1
Disclosed:
Dec 26, 2023

CVE-2023-51377 on NVD →

Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder [everest-forms] < 1.8.0

unknown

[en] The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Dec 21, 2021

CVE-2021-24907 on NVD →

Everest Forms <= 1.7.9 - Reflected Cross-Site Scripting

medium

The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Nov 22, 2021

CVE-2021-24907 on NVD →

Contact Form, Drag and Drop Form Builder for WordPress – Everest Forms <= 1.4.9 - SQL Injection

critical

A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/evf-entry-functions.php

CVSS:
9.8
Affected:
up to 1.5.0
Fixed in:
1.5.0
Disclosed:
Jul 18, 2019

CVE-2019-13575 on NVD →

Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder [everest-forms] < 1.5.0

unknown

[en] A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/evf-entry-functions.php

Affected:
up to 1.5.0
Fixed in:
1.5.0
Disclosed:
Jul 18, 2019

CVE-2019-13575 on NVD →

Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder [everest-forms] < 3.0.3.1

unknown
Affected:
up to 3.0.3.1
Fixed in:
3.0.3.1

CVE-2024-8542 on NVD →

Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder [everest-forms] < 3.1.2

unknown
Affected:
up to 3.1.2
Fixed in:
3.1.2

CVE-2025-3421 on NVD →

Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder [everest-forms] < 3.1.2

unknown
Affected:
up to 3.1.2
Fixed in:
3.1.2

CVE-2025-3422 on NVD →

Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder [everest-forms] < 3.1.2

unknown
Affected:
up to 3.1.2
Fixed in:
3.1.2

CVE-2025-3439 on NVD →

Everest Forms – Contact Form, Payment Form, Quiz, Survey &amp; Custom Form Builder [everest-forms] < 3.0.9.5

unknown
Affected:
up to 3.0.9.5
Fixed in:
3.0.9.5

CVE-2025-1128 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database