VYPR

Everest Forms

by WordPress

Source repositories

CVEs (23)

  • CVE-2026-11571HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users' form submission…

  • CVE-2026-57312HigJun 26, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions.

  • CVE-2019-13575CriJul 18, 2019
    risk 0.00cvss 9.8epss 0.03

    A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via includes/evf-entry-functions.php

Page 2 of 2