Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-60210 Deserialization of Untrusted Data vulnerability in wpeverest Everest Forms - Frontend Listing everest-forms-frontend-listing allows Object Injection.… Everest Forms Frontend Listing after 1.0.5 Fix from $2,3002025-10-22 HIGH 7.5 CVE-2025-5927 The Everest Forms (Pro) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_fi… Everest Forms 1.9.5+ Fix from $1,9502025-06-25 MEDIUM 6.1 CVE-2025-26841 Cross Site Scripting vulnerability in WPEVEREST Everest Forms before 3.0.9 allows an attacker to execute arbitrary code via a file upload. Everest Forms 3.0.9+ Fix from $1,6002025-05-12 MEDIUM 6.1 CVE-2025-39400 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration a… User Registration \& Membership 4.2.0 / 5.2.0+ Fix from $1,6002025-04-24 HIGH 8.1 CVE-2025-2594EPSS 9% The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabl… User Registration \& Membership 4.1.3 / 5.1.3+ Fix from $1,9502025-04-22 HIGH 8.1 CVE-2025-2563EPSS 46% The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabl… User Registration \& Membership 4.1.2 / 5.1.2+ Fix from $1,9502025-04-14 MEDIUM 5.3 CVE-2025-3282 The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Obj… User Registration \& Membership 4.1.4+ Fix from $1,6002025-04-12 CRITICAL 9.8 CVE-2025-3439 The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Inje… Everest Forms 3.1.2+ Fix from $2,3002025-04-11 MEDIUM 6.3 CVE-2025-3422 The The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary s… Everest Forms 3.1.2+ Fix from $1,6002025-04-11 MEDIUM 6.1 CVE-2025-3421 The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross… Everest Forms 3.1.2+ Fix from $1,6002025-04-11 MEDIUM 6.1 CVE-2025-1511 The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Reflected Cross-Sit… User Registration 4.1.0+ Fix from $1,6002025-02-28 CRITICAL 9.8 CVE-2025-1128EPSS 29% The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file… Everest Forms 3.0.9.5+ Fix from $2,3002025-02-25 MEDIUM 5.3 CVE-2023-29429 Missing Authorization vulnerability in WPEverest User Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue… User Registration 2.3.3+ Fix from $1,6002024-12-09 MEDIUM 5.3 CVE-2023-51377 Missing Authorization vulnerability in WPEverest Everest Forms.This issue affects Everest Forms: from n/a through 2.0.3. Everest Forms 2.0.3.1+ Fix from $1,6002024-06-14 HIGH 7.2 CVE-2024-1812 The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' pa… Everest Forms 2.0.8+ Fix from $1,9502024-04-09 HIGH 8.8 CVE-2023-27459 Deserialization of Untrusted Data vulnerability in WPEverest User Registration.This issue affects User Registration: from n/a through 2.3.2.1. User Registration \& Membership 2.3.3+ Fix from $1,9502024-03-26 MEDIUM 6.1 CVE-2024-1720 The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Si… User Registration \& Membership 3.1.5+ Fix from $1,6002024-03-07 CRITICAL 9.9 CVE-2023-3342 The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation… User Registration 3.0.2.1+ Fix from $2,3002023-07-13 HIGH 8.8 CVE-2023-3343 The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untru… User Registration after 3.0.1 Fix from $1,9502023-07-13 HIGH 7.5 CVE-2022-3912 The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX action available to both unauth… User Registration 2.2.4.1+ Fix from $1,9502022-12-12 MEDIUM 6.1 CVE-2021-24907 The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter before outputting it back in an a… Everest Forms 1.8.0+ Fix from $1,6002021-12-21 MEDIUM 5.4 CVE-2021-24654 The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url value when submitted directly vi… User Registration 2.0.2+ Fix from $1,6002021-10-04 CRITICAL 9.8 CVE-2019-13575 A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitation of this vulnerability wou… Everest Forms after 1.4.9 Fix from $2,3002019-07-18