Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesEverest Forms

Everest Forms vulnerabilities

Everest Forms has 20 known vulnerabilities in this database. The most recent published record is dated 7 Oct 2026.

Known vulnerabilities
20
Active installs
90,000+
Latest version
3.6.2
Last updated
21 Sep 2026
Most recent
7 Oct 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Cross-site scripting (XSS)
CVE-2026-94670
High 7.1Up to 3.6.1Fixed in a later version (latest 3.6.2)6 h ago
Server-side request forgery (SSRF)
CVE-2026-5096
Medium 5.3Up to 3.4.4Fixed in a later version (latest 3.6.2)28 Aug 2026
Broken access control
CVE-2026-13167
Medium 4.3Up to 3.5.2Fixed in a later version (latest 3.6.2)16 Aug 2026
Security weakness
CVE-2026-12270
Medium 6.5Before 3.5.0Fixed in 3.5.09 Jul 2026
Security weakness
CVE-2026-11571
High 7.5Before 3.5.0Fixed in 3.5.09 Jul 2026
Broken access control
CVE-2026-4888
Medium 4.3Up to 3.4.7Fixed in a later version (latest 3.6.2)28 May 2026
Arbitrary file read
CVE-2026-5478
High 8.1Up to 3.4.4Fixed in a later version (latest 3.6.2)20 Apr 2026
PHP object injection
CVE-2026-3296
Critical 9.8Up to 3.4.3Fixed in a later version (latest 3.6.2)8 Apr 2026
Remote code execution
CVE-2026-3300
Critical 9.8Up to 1.9.12Fixed in a later version (latest 3.6.2)31 Mar 2026
Remote code execution
CVE-2025-5927
High 7.5Before 1.9.5Fixed in 1.9.525 Jun 2025
Cross-site scripting (XSS)
CVE-2024-8542
Medium 4.8Before 3.0.3.1Fixed in 3.0.3.115 May 2025
PHP object injection
CVE-2025-3439
Critical 9.8Before 3.1.2Fixed in 3.1.211 Apr 2025
Cross-site scripting (XSS)
CVE-2025-3421
Medium 6.1Before 3.1.2Fixed in 3.1.211 Apr 2025
Remote code execution
CVE-2025-3422
Medium 5.4Before 3.1.2Fixed in 3.1.211 Apr 2025
Remote code execution
CVE-2025-1128
Critical 9.8Before 3.0.9.5Fixed in 3.0.9.525 Feb 2025
Cross-site scripting (XSS)
CVE-2024-13125
Low 3.5Before 3.0.8.1Fixed in 3.0.8.113 Feb 2025
Cross-site scripting (XSS)
CVE-2024-10471
Medium 4.8Before 3.0.4.2Fixed in 3.0.4.226 Nov 2024
Server-side request forgery (SSRF)
CVE-2024-1812
High 7.2Before 2.0.8Fixed in 2.0.89 Apr 2024
Cross-site scripting (XSS)
CVE-2021-24907
Medium 6.1Before 1.8.0Fixed in 1.8.021 Dec 2021
SQL injection
CVE-2019-13575
Critical 9.8Up to 1.4.9Fixed in a later version (latest 3.6.2)18 Jul 2019
Read the published descriptions
CVE-2026-94670, 7 Oct 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Everest Forms allows Reflected XSS. This issue affects Everest Forms: from n/a through 3.6.1. CVE record
CVE-2026-5096, 28 Aug 2026
The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the `load_previous_field_value()` method in `class-evf-form-task.php` accepting arbitrary URL values from `$_POST` data for upload fields without domain restriction, which are then passed to `wp_remote_head()` in the `get_local_file_size()` method of `class-evf-form-fields-upload.php`. This makes it possible for unauthenticated attackers to force the WordPress server to make outbound HTTP HEAD requests to arbitrary URLs by submitting a form with an upload field containing a malicious URL while leaving a required field empty to trigger form re-rendering. CVE record
CVE-2026-13167, 16 Aug 2026
The Everest Forms - Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with delegated form management access and above, to activate arbitrary already-installed WordPress plugins - including previously deactivated or vulnerable plugins - without holding the core activate_plugins capability. Exploitation requires the target user to hold a delegated Everest Forms capability (manage_everest_forms, everest_forms_create_forms, or everest_forms_view_forms), which the plugin's own roles and permissions tool allows administrators to assign to non-administrator roles such as Author; the nonces required to exploit the AJAX handlers are emitted on EVF admin pages accessible to any such delegated user. CVE record
CVE-2026-12270, 9 Jul 2026
The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belonging to its onboarding assistant: the capability check is only applied when an attacker-controllable request header holds a specific value, so it can be bypassed by omitting or changing that header. This makes it possible for unauthenticated attackers to read onboarding status information, modify the related Everest Forms WordPress plugin before 3.5.0 options, and trigger an email from the site to an arbitrary address. CVE record
CVE-2026-11571, 9 Jul 2026
The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users' form submission records via predictable, enumerable filenames. CVE record
CVE-2026-4888, 28 May 2026
The Everest Forms - Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 3.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send test emails to arbitrary addresses from the server. CVE record
CVE-2026-5478, 20 Apr 2026
The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3.4.4. This is due to the plugin trusting attacker-controlled old_files data from public form submissions as legitimate server-side upload state, and converting attacker-supplied URLs into local filesystem paths using regex-based string replacement without canonicalization or directory boundary enforcement. This makes it possible for unauthenticated attackers to read arbitrary local files (e.g., wp-config.php) by injecting path-traversal payloads into the old_files upload field parameter, which are then attached to notification emails. The same path resolution is also used in the post-email cleanup routine, which calls unlink() on the resolved path, resulting in the targeted file being deleted after being attached. This can lead to full site compromise through disclosure of database credentials and authentication salts from wp-config.php, and denial of service through deletion of critical files. Prerequisite: The form must contain a file-upload or image-upload field, and disable storing entry information. CVE record
CVE-2026-3296, 8 Apr 2026
The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling PHP's native unserialize() on stored entry meta values without passing the allowed_classes parameter. This makes it possible for unauthenticated attackers to inject a serialized PHP object payload through any public Everest Forms form field. The payload survives sanitize_text_field() sanitization (serialization control characters are not stripped) and is stored in the wp_evf_entrymeta database table. When an administrator views entries or views an individual entry, the unsafe unserialize() call processes the stored data without class restrictions. CVE record
CVE-2026-3300, 31 Mar 2026
The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_filter() function concatenating user-submitted form field values into a PHP code string without proper escaping before passing it to eval(). The sanitize_text_field() function applied to input does not escape single quotes or other PHP code context characters. This makes it possible for unauthenticated attackers to inject and execute arbitrary PHP code on the server by submitting a crafted value in any string-type form field (text, email, URL, select, radio) when a form uses the "Complex Calculation" feature. CVE record
CVE-2025-5927, 25 Jun 2025
The Everest Forms (Pro) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The vulnerability requires an admin to trigger the deletion via deletion of a form entry and cannot be carried out by the attacker alone. CVE record
CVE-2024-8542, 15 May 2025
The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
CVE-2025-3439, 11 Apr 2025
The Everest Forms - Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.1 via deserialization of untrusted input from the 'field_value' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. CVE record
CVE-2025-3421, 11 Apr 2025
The Everest Forms - Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'form_id' parameter in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
CVE-2025-3422, 11 Apr 2025
The The Everest Forms - Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.1.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes. CVE record
CVE-2025-1128, 25 Feb 2025
The Everest Forms - Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due to missing file type and path validation in the 'format' method of the EVF_Form_Fields_Upload class in all versions up to, and including, 3.0.9.4. This makes it possible for unauthenticated attackers to upload, read, and delete arbitrary files on the affected site's server which may make remote code execution, sensitive information disclosure, or a site takeover possible. CVE record
CVE-2024-13125, 13 Feb 2025
The Everest Forms WordPress plugin before 3.0.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
CVE-2024-10471, 26 Nov 2024
The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
CVE-2024-1812, 9 Apr 2024
The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. CVE record
CVE-2021-24907, 21 Dec 2021
The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue CVE record
CVE-2019-13575, 18 Jul 2019
A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/evf-entry-functions.php CVE record

What to do if you run Everest Forms

If you run Everest Forms, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Everest Forms vulnerabilities

Free. We email you when a new vulnerability is published for Everest Forms, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support