CVE-2026-27070
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Everest Forms Pro allows Stored XSS.This issue affects Everest Forms Pro: from n/a through 1.9.10.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in Everest Forms Pro ≤1.9.10 allows attackers to inject malicious scripts via form fields, impacting thousands of WordPress sites with privileged user interaction.
The Everest Forms Pro plugin for WordPress, versions 1.9.10 and earlier, contains a Stored Cross-Site Scripting (XSS) vulnerability. This improper neutralization of user-supplied input during web page generation allows an attacker to inject arbitrary JavaScript or HTML into form submissions that are stored and later displayed to site visitors.
Exploitation requires the attacker to have an authenticated user with at least contributor-level privileges (or similar) to submit or manage forms on the site. The injected script is stored in the database and triggers when a victim (including administrators or other visitors) views the page containing the malicious payload. No additional authentication beyond the victim's normal session is required for execution, but a privileged user must first initiate the action (e.g., submitting or saving the form).[1]
A successful attack can lead to session hijacking, harvesting, redirection to malicious sites, or defacement of the affected WordPress pages. Since the payload is persistent, it is persistent, the impact can affect multiple users sitewide until the content is removed or patched.
Patchstack has released a mitigation rule to block attacks prior to updating. The vendor has patched this vulnerability in version 1.9.13. Users are strongly advised to update to this version immediately or apply a virtual patch if immediate updating is not possible.[1]
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <= 1.9.10
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.