5.4
CVSSv3

CVE-2025-3422

CVSSv4: NA | CVSSv3: 5.4 | CVSSv2: NA | VMScore: 640 | EPSS: 0.00048 | KEV: Not Included
Published: 11/04/2025 Updated: 11/04/2025

Vulnerability Summary

Authenticated Arbitrary Shortcode Execution in Everest Forms WordPress Plugin

The Everest Forms WordPress plugin has a vulnerability that allows arbitrary shortcode execution in versions up to and including 3.1.1. An authenticated attacker with Subscriber-level access or higher can exploit this issue because the plugin does not properly validate a value before running do_shortcode. This means an attacker could potentially execute unauthorized shortcodes within the WordPress environment, which could lead to unintended actions or potential security risks.