CVE-2026-5478
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder
Minimum safe version
3.4.5
Update to 3.4.5 or later to address 17 fixable vulnerabilities
Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry Metadata
CVE-2026-22422
CVE-2025-52709
CVE-2025-26841
Everest Forms <= 3.1.1 - Reflected Cross-Site Scripting
Everest Forms <= 3.1.1 - Authenticated (Subscriber+) Arbitrary Shortcode Execution
Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.1.1 - Unauthenticated PHP Object Injection
Everest Forms <= 3.0.9.4 - Unauthenticated Arbitrary File Upload, Read, and Deletion
CVE-2024-13125
CVE-2024-10471
Everest Forms <= 3.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
CVE-2024-1812
WordPress Everest Forms Plugin <= 2.0.3 is vulnerable to Broken Access Control
WordPress Everest Forms Plugin <= 2.0.4.1 is vulnerable to Cross Site Scripting (XSS)
WordPress Everest Forms plugin <= 1.4.9 - SQL Injection (SQLi) vulnerability
CVE-2021-24907