Medium severity6.1NVD Advisory· Published May 12, 2025· Updated Jun 17, 2026
CVE-2025-26841
CVE-2025-26841
Description
Cross Site Scripting vulnerability in WPEVEREST Everest Forms before 3.0.9 allows an attacker to execute arbitrary code via a file upload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:wpeverest:everest_forms:*:*:*:*:*:wordpress:*:*+ 2 more
- cpe:2.3:a:wpeverest:everest_forms:*:*:*:*:*:wordpress:*:*range: <3.0.9
- (no CPE)
- (no CPE)range: <3.0.9
Patches
Vulnerability mechanics
References
2- gist.github.com/knilkantha/71458e9a787157653d5603fe6880bc05nvdThird Party Advisory
- everestforms.netnvdProduct
News mentions
0No linked articles in our index yet.