6.1
CVSSv3

CVE-2025-3421

CVSSv4: NA | CVSSv3: 6.1 | CVSSv2: NA | VMScore: 710 | EPSS: 0.0008 | KEV: Not Included
Published: 11/04/2025 Updated: 11/04/2025

Vulnerability Summary

Reflected XSS Vulnerability in Everest Forms WordPress Plugin Before 3.1.1

The Everest Forms WordPress plugin has a Cross-Site Scripting (XSS) vulnerability in all versions up to and including 3.1.1. The issue exists in the 'form_id' parameter because of weak input sanitization and output escaping. This allows unauthenticated attackers to inject malicious web scripts into pages. These scripts can execute if a user is tricked into clicking a specially crafted link, potentially compromising their browsing session or website interactions.