Everestthemes develops a focused portfolio of WordPress themes and plugins—including backup utilities, news aggregation, and multipurpose theme products—oriented toward site creation and content management. The recurring vulnerability signal centers on web-application input handling and CSRF protections, with exposures clustering around cross-site scripting, cross-site request forgery, and sensitive-data handling issues typical of extensible WordPress-ecosystem components. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Everestthemes over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-62992HIGH Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup everest-backup allows Path Traversal.This issue affects Everest Backup: from n/a through <= 2.3.11. | Dec 31, 2025 | 8.1 | 25 | NO | NO |
CVE-2025-62946HIGH Missing Authorization vulnerability in everestthemes Everest Backup everest-backup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Everes | Oct 27, 2025 | 8.8 | 25 | NO | NO |
CVE-2024-10028HIGH The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc | Nov 6, 2024 | 7.5 | 23 | NO | NO |
CVE-2023-52185HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Everestthemes Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin.This issue af | Dec 31, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-27419MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest themes Viable Blog theme <= 1.1.4 versions. | May 10, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-7201MEDIUM The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high privilege users such as admin to upload arbitrary files on t | Apr 15, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-32531HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Everest themes GuCherry Blog allows Reflected XSS.This issue affects GuCherry | Apr 17, 2024 | 7.1 | 19 | NO | NO |
CVE-2023-41237MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest Themes Arya Multipurpose Pro theme <= 1.0.8 versions. | Sep 27, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-27412MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest themes Mocho Blog theme <= 1.0.4 versions. | Aug 8, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-27420MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest Themes Arya Multipurpose theme <= 1.0.5 versions. | Jun 16, 2023 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Everestthemes.
Media articles that mention a CVE ID that affects a product developed by Everestthemes — matched by CVE ID, not by vendor name.