Everest Forms Pro <= 1.9.12 - Unauthenticated Remote Code Execution via Calculation Field
critical
The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_filter() function concatenating user-submitted form field values into a PHP code string without proper escaping before pas...
- CVSS:
- 9.8
- Affected:
- up to 1.9.12
- Fixed in:
- 1.9.13
- Disclosed:
- Mar 30, 2026
CVE-2026-3300 on NVD →
Everest Forms Pro <= 1.9.12 - Unauthenticated Stored Cross-Site Scripting
high
The Everest Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acc...
- CVSS:
- 7.2
- Affected:
- up to 1.9.12
- Fixed in:
- 1.9.13
- Disclosed:
- Mar 12, 2026
CVE-2026-27070 on NVD →
Everest Forms (Pro) <= 1.9.7 - Unauthenticated PHP Object Injection via PHAR Deserialization in Form Signature
medium
The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.7 via deserialization of untrusted input in the mime_content_type() function. This makes it possible for unauthenticated attackers to inject a PHP Object. This vulnerability may be exploited by u...
- CVSS:
- 5.6
- Affected:
- up to 1.9.7
- Fixed in:
- 1.9.8
- Disclosed:
- Nov 4, 2025
CVE-2025-8871 on NVD →
Everest Forms (Pro) <= 1.9.4 - Unauthenticated Path Traversal to Arbitrary File Deletion
high
The Everest Forms (Pro) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily...
- CVSS:
- 7.5
- Affected:
- up to 1.9.4
- Fixed in:
- 1.9.5
- Disclosed:
- Jun 24, 2025
CVE-2025-5927 on NVD →
Everest Forms Pro [everest-forms-pro] < 1.9.5
unknown
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.5
CVE-2025-5927 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database