Extension WordPress
Vulnérabilités Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI
Cette page rassemble les failles publiées pour Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI
17 fiches
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI <= 3.4.8 – Reflected Cross-Site Scripting
The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.4.8 due to insufficient input sanitization and…
*-3.4.8
3.5.0
25/06/2026
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder <= 3.4.7 – Missing Authorization to Authenticated (Subscriber+) Email Sending
The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to,…
*-3.4.7
3.4.8
27/05/2026
Everest Forms <= 3.4.4 – Unauthenticated Arbitrary File Read and Deletion via Upload Field 'old_files' Parameter
The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3.4.4. This is due to the plugin trusting attacker-controlled old_files data from public form submissions as legitimate…
*-3.4.4
3.4.5
20/04/2026
Everest Forms <= 3.4.3 – Unauthenticated PHP Object Injection via Form Entry Metadata
The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling PHP's…
*-3.4.3
3.4.4
07/04/2026
Everest Forms <= 3.4.1 – Unauthenticated Arbitrary Shortcode Execution
The The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.4.1. This is due to the software…
*-3.4.1
3.4.2
26/09/2025
Everest Forms <= 3.1.1 – Reflected Cross-Site Scripting
The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'form_id' parameter in all versions up to, and including, 3.1.1 due to…
*-3.1.1
3.1.2
10/04/2025
Everest Forms <= 3.1.1 – Authenticated (Subscriber+) Arbitrary Shortcode Execution
The The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.1.1. This is due to the…
*-3.1.1
3.1.2
10/04/2025
Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.1.1 – Unauthenticated PHP Object Injection
The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.1 via deserialization of untrusted input from…
*-3.1.1
3.1.2
10/04/2025
Everest Forms <= 3.0.9.4 – Unauthenticated Arbitrary File Upload, Read, and Deletion
The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due to missing file type and path validation in the 'format'…
*-3.0.9.4
3.0.9.5
17/02/2025
Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.0.8 – Authenticated (Admin+) Stored Cross-Site Scripting
The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.8 due to insufficient…
*-3.0.8
3.0.8.1
17/01/2025
Everest Forms <= 3.0.4.1 – Authenticated (Admin+) Stored Cross-Site Scripting
The Everest Forms – Build Contact Forms, Surveys, Polls, Quizzes, Newsletter & Application Forms, and Many More with Ease! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including,…
*-3.0.4.1
3.0.4.2
05/11/2024
Everest Forms <= 3.0.3 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Everest Forms – Build Contact Forms, Surveys, Polls, Quizzes, Newsletter & Application Forms, and Many More with Ease! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including,…
*-3.0.3
3.0.3.1
01/08/2024
Everest Forms <= 2.0.7 – Unauthenticated Server-Side Request Forgery via font_url
The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations…
*-2.0.7
2.0.8
15/03/2024
Everest Forms <= 2.0.4.1 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Everest Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.0.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-2.0.4.1
2.0.5
27/12/2023
Everest Forms <= 2.0.3 – Unauthorized Form Submission via Disabled Forms
The Everest Forms plugin for WordPress is vulnerable to unauthorized form submission due to a missing validation check in the do_task function in versions up to, and including, 2.0.3. This makes it possible for unauthenticated attackers to submit…
*-2.0.3
2.0.3.1
26/12/2023
Everest Forms <= 1.7.9 – Reflected Cross-Site Scripting
The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
[*, 1.8.0)
1.8.0
22/11/2021
Contact Form, Drag and Drop Form Builder for WordPress – Everest Forms <= 1.4.9 – SQL Injection
A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/evf-entry-functions.php
[*, 1.5.0)
1.5.0
18/07/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.