Extension WordPress

Vulnérabilités Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI

Cette page rassemble les failles publiées pour Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI, leurs plages de versions affectées et les correctifs signalés dans la base locale.

17Vulnérabilités
4Critiques
17Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI

17 fiches

CVE-2026-57312 Moyenne · 6,1
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI

Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI <= 3.4.8 – Reflected Cross-Site Scripting

The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.4.8 due to insufficient input sanitization and…

Versions affectées

*-3.4.8

Correctif

3.5.0

Publication

25/06/2026

CVE-2026-4888 Moyenne · 4,3
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI

Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder <= 3.4.7 – Missing Authorization to Authenticated (Subscriber+) Email Sending

The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to,…

Versions affectées

*-3.4.7

Correctif

3.4.8

Publication

27/05/2026

CVE-2026-5478 Élevée · 8,1
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI

Everest Forms <= 3.4.4 – Unauthenticated Arbitrary File Read and Deletion via Upload Field 'old_files' Parameter

The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3.4.4. This is due to the plugin trusting attacker-controlled old_files data from public form submissions as legitimate…

Versions affectées

*-3.4.4

Correctif

3.4.5

Publication

20/04/2026

CVE-2026-3296 Critique · 9,8
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI

Everest Forms <= 3.4.3 – Unauthenticated PHP Object Injection via Form Entry Metadata

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling PHP's…

Versions affectées

*-3.4.3

Correctif

3.4.4

Publication

07/04/2026

CVE-2026-22422 Moyenne · 6,5
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI

Everest Forms <= 3.4.1 – Unauthenticated Arbitrary Shortcode Execution

The The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.4.1. This is due to the software…

Versions affectées

*-3.4.1

Correctif

3.4.2

Publication

26/09/2025

CVE-2025-3421 Moyenne · 6,1
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI

Everest Forms <= 3.1.1 – Reflected Cross-Site Scripting

The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'form_id' parameter in all versions up to, and including, 3.1.1 due to…

Versions affectées

*-3.1.1

Correctif

3.1.2

Publication

10/04/2025

CVE-2025-3422 Moyenne · 5,4
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI

Everest Forms <= 3.1.1 – Authenticated (Subscriber+) Arbitrary Shortcode Execution

The The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.1.1. This is due to the…

Versions affectées

*-3.1.1

Correctif

3.1.2

Publication

10/04/2025

CVE-2025-3439 Critique · 9,8
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI

Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.1.1 – Unauthenticated PHP Object Injection

The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.1 via deserialization of untrusted input from…

Versions affectées

*-3.1.1

Correctif

3.1.2

Publication

10/04/2025

CVE-2025-1128 Critique · 9,8
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI

Everest Forms <= 3.0.9.4 – Unauthenticated Arbitrary File Upload, Read, and Deletion

The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due to missing file type and path validation in the 'format'…

Versions affectées

*-3.0.9.4

Correctif

3.0.9.5

Publication

17/02/2025

CVE-2024-13125 Moyenne · 4,4
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI

Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.0.8 – Authenticated (Admin+) Stored Cross-Site Scripting

The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.8 due to insufficient…

Versions affectées

*-3.0.8

Correctif

3.0.8.1

Publication

17/01/2025

CVE-2024-10471 Moyenne · 4,4
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI

Everest Forms <= 3.0.4.1 – Authenticated (Admin+) Stored Cross-Site Scripting

The Everest Forms – Build Contact Forms, Surveys, Polls, Quizzes, Newsletter & Application Forms, and Many More with Ease! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including,…

Versions affectées

*-3.0.4.1

Correctif

3.0.4.2

Publication

05/11/2024

CVE-2024-8542 Moyenne · 4,4
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI

Everest Forms <= 3.0.3 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Everest Forms – Build Contact Forms, Surveys, Polls, Quizzes, Newsletter & Application Forms, and Many More with Ease! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including,…

Versions affectées

*-3.0.3

Correctif

3.0.3.1

Publication

01/08/2024

CVE-2024-1812 Élevée · 7,2
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI

Everest Forms <= 2.0.7 – Unauthenticated Server-Side Request Forgery via font_url

The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations…

Versions affectées

*-2.0.7

Correctif

2.0.8

Publication

15/03/2024

CVE-2023-51695 Moyenne · 4,4
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI

Everest Forms <= 2.0.4.1 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Everest Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.0.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

Versions affectées

*-2.0.4.1

Correctif

2.0.5

Publication

27/12/2023

CVE-2023-51377 Moyenne · 5,3
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI

Everest Forms <= 2.0.3 – Unauthorized Form Submission via Disabled Forms

The Everest Forms plugin for WordPress is vulnerable to unauthorized form submission due to a missing validation check in the do_task function in versions up to, and including, 2.0.3. This makes it possible for unauthenticated attackers to submit…

Versions affectées

*-2.0.3

Correctif

2.0.3.1

Publication

26/12/2023

CVE-2019-13575 Critique · 9,8
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI

Contact Form, Drag and Drop Form Builder for WordPress – Everest Forms <= 1.4.9 – SQL Injection

A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/evf-entry-functions.php

Versions affectées

[*, 1.5.0)

Correctif

1.5.0

Publication

18/07/2019

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités