plugin

Everest Forms Pro Vulnerabilities

5 known security issues reported for the Everest Forms Pro WordPress plugin. Most recent disclosed Mar 30, 2026.

1 critical 2 high 1 medium

Running Everest Forms Pro on your site? Check whether your installed version is affected.

Scan your site free

Everest Forms Pro <= 1.9.12 - Unauthenticated Remote Code Execution via Calculation Field

critical

The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_filter() function concatenating user-submitted form field values into a PHP code string without proper escaping before pas...

CVSS:
9.8
Affected:
up to 1.9.12
Fixed in:
1.9.13
Disclosed:
Mar 30, 2026

CVE-2026-3300 on NVD →

Everest Forms Pro <= 1.9.12 - Unauthenticated Stored Cross-Site Scripting

high

The Everest Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acc...

CVSS:
7.2
Affected:
up to 1.9.12
Fixed in:
1.9.13
Disclosed:
Mar 12, 2026

CVE-2026-27070 on NVD →

Everest Forms (Pro) <= 1.9.7 - Unauthenticated PHP Object Injection via PHAR Deserialization in Form Signature

medium

The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.7 via deserialization of untrusted input in the mime_content_type() function. This makes it possible for unauthenticated attackers to inject a PHP Object. This vulnerability may be exploited by u...

CVSS:
5.6
Affected:
up to 1.9.7
Fixed in:
1.9.8
Disclosed:
Nov 4, 2025

CVE-2025-8871 on NVD →

Everest Forms (Pro) <= 1.9.4 - Unauthenticated Path Traversal to Arbitrary File Deletion

high

The Everest Forms (Pro) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily...

CVSS:
7.5
Affected:
up to 1.9.4
Fixed in:
1.9.5
Disclosed:
Jun 24, 2025

CVE-2025-5927 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database