Everest Forms
Vendor:
First CVE: Jul 18, 2019 · Active for 7 years
16
Total CVEs
More Total CVEs than 93% of tracked products
3.2
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 35% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Everest Forms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 18, 2019
7 years ago
Most Recent CVE
Jun 26, 2026
32 days ago
CVE Severity & Scoring
Everest Forms16 CVEs
56%
19%
19%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High1 (6.3%)
Unknown0 (0.0%)
User Interaction
None7 (43.8%)
Unknown0 (0.0%)
Required9 (56.3%)
Privileges Required
Low1 (6.3%)
High4 (25.0%)
None11 (68.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1128CRITICAL The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due | Feb 25, 2025 | 9.8 | 46 | NO | NO |
CVE-2019-13575CRITICAL A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to e | Jul 18, 2019 | 9.8 | 30 | NO | NO |
CVE-2025-3439CRITICAL The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, an | Apr 11, 2025 | 9.8 | 29 | NO | NO |
CVE-2026-57312HIGH Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions. | Jun 26, 2026 | 7.1 | 25 | NO | NO |
CVE-2025-5927HIGH The Everest Forms (Pro) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions | Jun 25, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-1812HIGH The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' parameter. This makes it possible | Apr 9, 2024 | 7.2 | 22 | NO | NO |
CVE-2021-24907MEDIUM The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter before outputting it back in an attribute, leading to a Reflecte | Dec 21, 2021 | 6.1 | 21 | NO | NO |
CVE-2026-22422MEDIUM Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in wpeverest Everest Forms everest-forms allows Code Injection.This issue affects Everes | Feb 19, 2026 | 5.3 | 19 | NO | NO |
CVE-2025-3422MEDIUM The The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versi | Apr 11, 2025 | 6.3 | 19 | NO | NO |
CVE-2025-3421MEDIUM The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'form_i | Apr 11, 2025 | 6.1 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Everest Forms
Top CWEs
Versions
No cataloged versions.