plugin

Everest Forms Frontend Listing Vulnerabilities

2 known security issues reported for the Everest Forms Frontend Listing WordPress plugin. Most recent disclosed Oct 22, 2025.

1 high

Running Everest Forms Frontend Listing on your site? Check whether your installed version is affected.

Scan your site free

Everest Forms Frontend Listing [everest-forms-frontend-listing] <= 1.0.5 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms - Frontend Listing everest-forms-frontend-listing allows Object Injection.This issue affects Everest Forms - Frontend Listing: from n/a through <= 1.0.5.

Affected:
up to 1.0.5
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-60210 on NVD →

Everest Forms - Frontend Listing <= 1.0.5 - Unauthenticated PHP Object Injection

high

The Everest Forms - Frontend Listing plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.0.5 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP...

CVSS:
8.1
Affected:
up to 1.0.5
Fix:
No patched version reported
Disclosed:
Jul 2, 2025

CVE-2025-60210 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database