Wpeverest
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Wpeverest product.
RSS Feeds for Wpeverest security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Wpeverest products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Wpeverest Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 31 vulnerabilities in Wpeverest with an average score of 6.7 out of ten. Last year, in 2025 Wpeverest had 21 security vulnerabilities published. That is, 10 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.01.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 31 | 6.69 |
| 2025 | 21 | 6.69 |
| 2024 | 10 | 6.34 |
| 2023 | 4 | 7.35 |
| 2022 | 2 | 6.20 |
| 2021 | 2 | 5.75 |
| 2020 | 0 | 0.00 |
| 2019 | 1 | 0.00 |
It may take a day or so for new Wpeverest vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Wpeverest Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-74017 | Sep 17, 2026 |
Unauthenticated Broken Access Control in User Reg <=5.2.7 (WP Plugin)Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions. |
|
| CVE-2026-62103 | Sep 11, 2026 |
Unauth PHP Obj Injection: Everest Forms <= 3.6.0Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions. |
|
| CVE-2026-5096 | Aug 28, 2026 |
WordPress Everest Forms Plugin <=3.4.4 SSRF via load_previous_field_valueThe Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the `load_previous_field_value()` method in `class-evf-form-task.php` accepting arbitrary URL values from `$_POST` data for upload fields without domain restriction, which are then passed to `wp_remote_head()` in the `get_local_file_size()` method of `class-evf-form-fields-upload.php`. This makes it possible for unauthenticated attackers to force the WordPress server to make outbound HTTP HEAD requests to arbitrary URLs by submitting a form with an upload field containing a malicious URL while leaving a required field empty to trigger form re-rendering. |
|
| CVE-2026-74001 | Aug 20, 2026 |
Unauthenticated Auth Bypass in User Registration & Membership Pro <=5.4.5Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions. |
|
| CVE-2026-73995 | Aug 18, 2026 |
Subscriber Broken Auth in User Registration <=5.2.6Subscriber Broken Authentication in User Registration <= 5.2.6 versions. |
|
| CVE-2026-13167 | Aug 16, 2026 |
Auth Bypass in Everest Forms 3.5.2 Arbitrary Plugin ActivationThe Everest Forms Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with delegated form management access and above, to activate arbitrary already-installed WordPress plugins including previously deactivated or vulnerable plugins without holding the core activate_plugins capability. Exploitation requires the target user to hold a delegated Everest Forms capability (manage_everest_forms, everest_forms_create_forms, or everest_forms_view_forms), which the plugin's own roles and permissions tool allows administrators to assign to non-administrator roles such as Author; the nonces required to exploit the AJAX handlers are emitted on EVF admin pages accessible to any such delegated user. |
|
| CVE-2026-73403 | Aug 13, 2026 |
Unauthenticated BADC in User Registration <=5.2.6Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions. |
|
| CVE-2026-12124 | Jul 28, 2026 |
PDFDraft WP Plugin 1.1.0 Auth Bypass via serveTemplatePdf()The PDFDraft Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the serveTemplatePdfAjax() function and the serveTemplatePdf() REST route (which is registered with `permission_callback => '__return_true'`) in versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to download stored template PDFs which may contain customer PII, invoice, order, and certificate data by requesting the publicly registered admin-ajax action `pdfdraft_embed_pdf` or the REST endpoint `/wp-json/pdfdraft/v1/embed-pdf/templates/{slug}/pdf` with a known or guessable design slug, bypassing the plugin's own . |
|
| CVE-2026-57312 | Jun 26, 2026 |
Unauthenticated XSS in Everest Forms <= 3.4.8Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions. |
|
| CVE-2026-1869 | Jun 26, 2026 |
WP User Reg & Mem plugin allows UAC in confirm_payment up to 5.2.0The User Registration & Membership Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the confirm_payment() function in all versions up to, and including, 5.2.0. This makes it possible for unauthenticated attackers to bypass payment processing and activate paid memberships. |
|