HomeWordPress vulnerabilitiesEverest Forms
Everest Forms vulnerabilities
Everest Forms has 20 known vulnerabilities in this database. The most recent published record is dated 7 Oct 2026.
- Known vulnerabilities
- 20
- Active installs
- 90,000+
- Latest version
- 3.6.2
- Last updated
- 21 Sep 2026
- Most recent
- 7 Oct 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Cross-site scripting (XSS) CVE-2026-94670 | High 7.1 | Up to 3.6.1 | Fixed in a later version (latest 3.6.2) | 6 h ago |
| Server-side request forgery (SSRF) CVE-2026-5096 | Medium 5.3 | Up to 3.4.4 | Fixed in a later version (latest 3.6.2) | 28 Aug 2026 |
| Broken access control CVE-2026-13167 | Medium 4.3 | Up to 3.5.2 | Fixed in a later version (latest 3.6.2) | 16 Aug 2026 |
| Security weakness CVE-2026-12270 | Medium 6.5 | Before 3.5.0 | Fixed in 3.5.0 | 9 Jul 2026 |
| Security weakness CVE-2026-11571 | High 7.5 | Before 3.5.0 | Fixed in 3.5.0 | 9 Jul 2026 |
| Broken access control CVE-2026-4888 | Medium 4.3 | Up to 3.4.7 | Fixed in a later version (latest 3.6.2) | 28 May 2026 |
| Arbitrary file read CVE-2026-5478 | High 8.1 | Up to 3.4.4 | Fixed in a later version (latest 3.6.2) | 20 Apr 2026 |
| PHP object injection CVE-2026-3296 | Critical 9.8 | Up to 3.4.3 | Fixed in a later version (latest 3.6.2) | 8 Apr 2026 |
| Remote code execution CVE-2026-3300 | Critical 9.8 | Up to 1.9.12 | Fixed in a later version (latest 3.6.2) | 31 Mar 2026 |
| Remote code execution CVE-2025-5927 | High 7.5 | Before 1.9.5 | Fixed in 1.9.5 | 25 Jun 2025 |
| Cross-site scripting (XSS) CVE-2024-8542 | Medium 4.8 | Before 3.0.3.1 | Fixed in 3.0.3.1 | 15 May 2025 |
| PHP object injection CVE-2025-3439 | Critical 9.8 | Before 3.1.2 | Fixed in 3.1.2 | 11 Apr 2025 |
| Cross-site scripting (XSS) CVE-2025-3421 | Medium 6.1 | Before 3.1.2 | Fixed in 3.1.2 | 11 Apr 2025 |
| Remote code execution CVE-2025-3422 | Medium 5.4 | Before 3.1.2 | Fixed in 3.1.2 | 11 Apr 2025 |
| Remote code execution CVE-2025-1128 | Critical 9.8 | Before 3.0.9.5 | Fixed in 3.0.9.5 | 25 Feb 2025 |
| Cross-site scripting (XSS) CVE-2024-13125 | Low 3.5 | Before 3.0.8.1 | Fixed in 3.0.8.1 | 13 Feb 2025 |
| Cross-site scripting (XSS) CVE-2024-10471 | Medium 4.8 | Before 3.0.4.2 | Fixed in 3.0.4.2 | 26 Nov 2024 |
| Server-side request forgery (SSRF) CVE-2024-1812 | High 7.2 | Before 2.0.8 | Fixed in 2.0.8 | 9 Apr 2024 |
| Cross-site scripting (XSS) CVE-2021-24907 | Medium 6.1 | Before 1.8.0 | Fixed in 1.8.0 | 21 Dec 2021 |
| SQL injection CVE-2019-13575 | Critical 9.8 | Up to 1.4.9 | Fixed in a later version (latest 3.6.2) | 18 Jul 2019 |
Read the published descriptions
- CVE-2026-94670, 7 Oct 2026
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Everest Forms allows Reflected XSS. This issue affects Everest Forms: from n/a through 3.6.1. CVE record
- CVE-2026-5096, 28 Aug 2026
- The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the `load_previous_field_value()` method in `class-evf-form-task.php` accepting arbitrary URL values from `$_POST` data for upload fields without domain restriction, which are then passed to `wp_remote_head()` in the `get_local_file_size()` method of `class-evf-form-fields-upload.php`. This makes it possible for unauthenticated attackers to force the WordPress server to make outbound HTTP HEAD requests to arbitrary URLs by submitting a form with an upload field containing a malicious URL while leaving a required field empty to trigger form re-rendering. CVE record
- CVE-2026-13167, 16 Aug 2026
- The Everest Forms - Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with delegated form management access and above, to activate arbitrary already-installed WordPress plugins - including previously deactivated or vulnerable plugins - without holding the core activate_plugins capability. Exploitation requires the target user to hold a delegated Everest Forms capability (manage_everest_forms, everest_forms_create_forms, or everest_forms_view_forms), which the plugin's own roles and permissions tool allows administrators to assign to non-administrator roles such as Author; the nonces required to exploit the AJAX handlers are emitted on EVF admin pages accessible to any such delegated user. CVE record
- CVE-2026-12270, 9 Jul 2026
- The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belonging to its onboarding assistant: the capability check is only applied when an attacker-controllable request header holds a specific value, so it can be bypassed by omitting or changing that header. This makes it possible for unauthenticated attackers to read onboarding status information, modify the related Everest Forms WordPress plugin before 3.5.0 options, and trigger an email from the site to an arbitrary address. CVE record
- CVE-2026-11571, 9 Jul 2026
- The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users' form submission records via predictable, enumerable filenames. CVE record
- CVE-2026-4888, 28 May 2026
- The Everest Forms - Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 3.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send test emails to arbitrary addresses from the server. CVE record
- CVE-2026-5478, 20 Apr 2026
- The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3.4.4. This is due to the plugin trusting attacker-controlled old_files data from public form submissions as legitimate server-side upload state, and converting attacker-supplied URLs into local filesystem paths using regex-based string replacement without canonicalization or directory boundary enforcement. This makes it possible for unauthenticated attackers to read arbitrary local files (e.g., wp-config.php) by injecting path-traversal payloads into the old_files upload field parameter, which are then attached to notification emails. The same path resolution is also used in the post-email cleanup routine, which calls unlink() on the resolved path, resulting in the targeted file being deleted after being attached. This can lead to full site compromise through disclosure of database credentials and authentication salts from wp-config.php, and denial of service through deletion of critical files. Prerequisite: The form must contain a file-upload or image-upload field, and disable storing entry information. CVE record
- CVE-2026-3296, 8 Apr 2026
- The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling PHP's native unserialize() on stored entry meta values without passing the allowed_classes parameter. This makes it possible for unauthenticated attackers to inject a serialized PHP object payload through any public Everest Forms form field. The payload survives sanitize_text_field() sanitization (serialization control characters are not stripped) and is stored in the wp_evf_entrymeta database table. When an administrator views entries or views an individual entry, the unsafe unserialize() call processes the stored data without class restrictions. CVE record
- CVE-2026-3300, 31 Mar 2026
- The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_filter() function concatenating user-submitted form field values into a PHP code string without proper escaping before passing it to eval(). The sanitize_text_field() function applied to input does not escape single quotes or other PHP code context characters. This makes it possible for unauthenticated attackers to inject and execute arbitrary PHP code on the server by submitting a crafted value in any string-type form field (text, email, URL, select, radio) when a form uses the "Complex Calculation" feature. CVE record
- CVE-2025-5927, 25 Jun 2025
- The Everest Forms (Pro) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The vulnerability requires an admin to trigger the deletion via deletion of a form entry and cannot be carried out by the attacker alone. CVE record
- CVE-2024-8542, 15 May 2025
- The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
- CVE-2025-3439, 11 Apr 2025
- The Everest Forms - Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.1 via deserialization of untrusted input from the 'field_value' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. CVE record
- CVE-2025-3421, 11 Apr 2025
- The Everest Forms - Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'form_id' parameter in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
- CVE-2025-3422, 11 Apr 2025
- The The Everest Forms - Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.1.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes. CVE record
- CVE-2025-1128, 25 Feb 2025
- The Everest Forms - Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due to missing file type and path validation in the 'format' method of the EVF_Form_Fields_Upload class in all versions up to, and including, 3.0.9.4. This makes it possible for unauthenticated attackers to upload, read, and delete arbitrary files on the affected site's server which may make remote code execution, sensitive information disclosure, or a site takeover possible. CVE record
- CVE-2024-13125, 13 Feb 2025
- The Everest Forms WordPress plugin before 3.0.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
- CVE-2024-10471, 26 Nov 2024
- The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
- CVE-2024-1812, 9 Apr 2024
- The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. CVE record
- CVE-2021-24907, 21 Dec 2021
- The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue CVE record
- CVE-2019-13575, 18 Jul 2019
- A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/evf-entry-functions.php CVE record
What to do if you run Everest Forms
If you run Everest Forms, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Everest Forms vulnerabilities
Free. We email you when a new vulnerability is published for Everest Forms, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.