Authenticated Arbitrary Shortcode Execution in Everest Forms WordPress Plugin
The Everest Forms WordPress plugin has a vulnerability that allows arbitrary shortcode execution in versions up to and including 3.1.1. An authenticated attacker with Subscriber-level access or higher can exploit this issue because the plugin does not properly validate a value before running do_shortcode. This means an attacker could potentially execute unauthorized shortcodes within the WordPress environment, which could lead to unintended actions or potential security risks.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
wpeverest everest forms – contact form, quiz, survey, newsletter & payment form builder for wordpress |
||
wpeverest everest forms |