Wpeverest's vulnerability footprint centers on a compact portfolio of WordPress form-builder, user-registration, and contact-management plugins that serve a broad installed base across self-hosted WordPress deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated tendency toward critical severity, and a moderate tendency to acquire public exploit tooling. The exposure recurs consistently across product variants including Everest Forms, User Registration, and Contact Form through weakness classes characteristic of plugin-tier web applications: cross-site scripting during form rendering and output handling, insecure deserialization, unrestricted file uploads, and authorization flaws tied to user-controlled keys. Defenders should treat updates to these widely installed plugins as high-priority, particularly where form submission and user registration functionality is customer-facing; live exploitation activity and current severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpeverest over time
Signals from CVEs in this vendor scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-2563HIGH The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege esca | Apr 14, 2025 | 8.1 | 72 | NO | YES |
CVE-2025-1128CRITICAL The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due | Feb 25, 2025 | 9.8 | 46 | NO | NO |
CVE-2025-2594HIGH The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authe | Apr 22, 2025 | 8.1 | 41 | NO | YES |
CVE-2019-13575CRITICAL A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to e | Jul 18, 2019 | 9.8 | 30 | NO | NO |
CVE-2026-57312HIGH Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions. | Jun 26, 2026 | 7.1 | 29 | NO | NO |
CVE-2026-24353HIGH Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User | Jan 22, 2026 | 8.1 | 29 | NO | NO |
CVE-2025-67956HIGH Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User | Jan 22, 2026 | 8.2 | 29 | NO | NO |
CVE-2025-60210CRITICAL Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms - Frontend Listing everest-forms-frontend-listing allows Object Injection.This issue affects Everest Form | Oct 22, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-3439CRITICAL The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, an | Apr 11, 2025 | 9.8 | 29 | NO | NO |
CVE-2023-3342CRITICAL The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' | Jul 13, 2023 | 9.9 | 28 | NO | NO |
Signals from CVEs in this vendor scope (37 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpeverest.
Media articles that mention a CVE ID that affects a product developed by Wpeverest — matched by CVE ID, not by vendor name.