Wpeverest Wpeverest

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Wpeverest product.

RSS Feeds for Wpeverest security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Wpeverest products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Wpeverest Sorted by Most Security Vulnerabilities since 2018

Wpeverest User Registration39 vulnerabilities

Wpeverest Everest Forms27 vulnerabilities

Wpeverest Contact Form1 vulnerability

By the Year

In 2026 there have been 31 vulnerabilities in Wpeverest with an average score of 6.7 out of ten. Last year, in 2025 Wpeverest had 21 security vulnerabilities published. That is, 10 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.01.




Year Vulnerabilities Average Score
2026 31 6.69
2025 21 6.69
2024 10 6.34
2023 4 7.35
2022 2 6.20
2021 2 5.75
2020 0 0.00
2019 1 0.00

It may take a day or so for new Wpeverest vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Wpeverest Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-74017 Sep 17, 2026
Unauthenticated Broken Access Control in User Reg <=5.2.7 (WP Plugin) Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.
User Registration
CVE-2026-62103 Sep 11, 2026
Unauth PHP Obj Injection: Everest Forms <= 3.6.0 Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.
Everest Forms
CVE-2026-5096 Aug 28, 2026
WordPress Everest Forms Plugin <=3.4.4 SSRF via load_previous_field_value The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the `load_previous_field_value()` method in `class-evf-form-task.php` accepting arbitrary URL values from `$_POST` data for upload fields without domain restriction, which are then passed to `wp_remote_head()` in the `get_local_file_size()` method of `class-evf-form-fields-upload.php`. This makes it possible for unauthenticated attackers to force the WordPress server to make outbound HTTP HEAD requests to arbitrary URLs by submitting a form with an upload field containing a malicious URL while leaving a required field empty to trigger form re-rendering.
Everest Forms
CVE-2026-74001 Aug 20, 2026
Unauthenticated Auth Bypass in User Registration & Membership Pro <=5.4.5 Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
User Registration
CVE-2026-73995 Aug 18, 2026
Subscriber Broken Auth in User Registration <=5.2.6 Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
User Registration
CVE-2026-13167 Aug 16, 2026
Auth Bypass in Everest Forms 3.5.2 Arbitrary Plugin Activation The Everest Forms Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with delegated form management access and above, to activate arbitrary already-installed WordPress plugins including previously deactivated or vulnerable plugins without holding the core activate_plugins capability. Exploitation requires the target user to hold a delegated Everest Forms capability (manage_everest_forms, everest_forms_create_forms, or everest_forms_view_forms), which the plugin's own roles and permissions tool allows administrators to assign to non-administrator roles such as Author; the nonces required to exploit the AJAX handlers are emitted on EVF admin pages accessible to any such delegated user.
Everest Forms
CVE-2026-73403 Aug 13, 2026
Unauthenticated BADC in User Registration <=5.2.6 Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.
User Registration
CVE-2026-12124 Jul 28, 2026
PDFDraft WP Plugin 1.1.0 Auth Bypass via serveTemplatePdf() The PDFDraft Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the serveTemplatePdfAjax() function and the serveTemplatePdf() REST route (which is registered with `permission_callback => '__return_true'`) in versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to download stored template PDFs which may contain customer PII, invoice, order, and certificate data by requesting the publicly registered admin-ajax action `pdfdraft_embed_pdf` or the REST endpoint `/wp-json/pdfdraft/v1/embed-pdf/templates/{slug}/pdf` with a known or guessable design slug, bypassing the plugin's own .
CVE-2026-57312 Jun 26, 2026
Unauthenticated XSS in Everest Forms <= 3.4.8 Unauthenticated Cross Site Scripting (XSS) in Everest Forms <= 3.4.8 versions.
Everest Forms
CVE-2026-1869 Jun 26, 2026
WP User Reg & Mem plugin allows UAC in confirm_payment up to 5.2.0 The User Registration & Membership Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the confirm_payment() function in all versions up to, and including, 5.2.0. This makes it possible for unauthenticated attackers to bypass payment processing and activate paid memberships.
User Registration
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.