0.000
EPSS

CVE-2024-13125

CVSSv4: NA | CVSSv3: 3.5 | CVSSv2: NA | VMScore: 450 | EPSS: 0.00037 | KEV: Not Included
Published: 13/02/2025 Updated: 19/02/2025

Vulnerability Summary

Stored XSS Vulnerability in Everest Forms WordPress Plugin Before 3.0.8.1

The Everest Forms WordPress plugin versions prior to 3.0.8.1 contain a Cross Site Scripting (XSS) vulnerability. Administrators and high-privilege users could potentially execute stored XSS attacks through unsanitized plugin settings. This vulnerability remains possible even in multisite environments where the unfiltered_html capability is typically restricted, enabling malicious script injection through the plugin's configuration options.

Vulnerable Product Search on Vulmon Subscribe to Product

unknown everest forms