NA
CVSSv3

CVE-2024-13125

CVSSv4: NA | CVSSv3: NA | CVSSv2: NA | VMScore: NA | EPSS: 0.00032 | KEV: Not Included
Published: 13/02/2025 Updated: 13/02/2025

Vulnerability Summary

Stored XSS Vulnerability in Everest Forms WordPress Plugin Before 3.0.8.1

The Everest Forms WordPress plugin versions prior to 3.0.8.1 contain a Cross Site Scripting (XSS) vulnerability. Administrators and high-privilege users could potentially execute stored XSS attacks through unsanitized plugin settings. This vulnerability remains possible even in multisite environments where the unfiltered_html capability is typically restricted, enabling malicious script injection through the plugin's configuration options.

Vulnerable Product Search on Vulmon Subscribe to Product

unknown everest forms