N/A
2025-11-04< 1.9.8
Everest Forms (Pro) <= 1.9.7 - Unauthenticated PHP Object Injection via PHAR Deserialization in Form Signature
Minimum safe version
1.9.13
Update to 1.9.13 or later to address 4 fixable vulnerabilities
Everest Forms (Pro) <= 1.9.7 - Unauthenticated PHP Object Injection via PHAR Deserialization in Form Signature
Everest Forms Pro <= 1.9.12 - Unauthenticated Remote Code Execution via Calculation Field
CVE-2026-27070
WordPress Everest Forms Pro Plugin <= 1.9.4 is vulnerable to Arbitrary File Deletion