Input validation vulnerability in Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress 3.1.1

The plugin “Everest Forms” for WordPress is not secure and can be easily exploited by hackers. This can happen when untrusted information is entered into the ‘field_value’ section, allowing attackers to inject a PHP Object. However, this vulnerability only has an impact if there is another plugin or theme with a POP chain installed. In that case, the attacker could potentially delete files, access sensitive information, or run code on the website.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.