Wpeverest
9 CVEs tracked since 2025. Since Apr 2025, none of them reached CISA KEV.
Wpeverest CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-04 | 9 | 0 |
Products
The products that kept showing up in Wpeverest's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Wpeverest.
- CVE-2026-74017WordPress User Registration plugin <= 5.2.7 - Broken Access Control vulnerability5.3
- CVE-2026-62103WordPress Everest Forms plugin <= 3.6.0 - PHP Object Injection vulnerability9.8
- CVE-2026-5096Everest Forms <= 3.4.4 - Unauthenticated Server-Side Request Forgery via Upload Field 'Previous Value'5.3
- CVE-2026-74001WordPress User Registration & Membership Pro plugin <= 5.4.5 - Account Takeover vulnerability9.8
- CVE-2026-73995WordPress User Registration plugin <= 5.2.6 - Broken Authentication vulnerability5.4
- CVE-2026-13167Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI <= 3.5.2 - Missing Authorization to Authenticated (Delegated+) Arbitrary Plugin Activation via REST API and AJAX Endpoints4.3
- CVE-2026-73403WordPress User Registration plugin <= 5.2.6 - Broken Access Control vulnerability5.3
- CVE-2026-12124PDFDraft <= 1.1.0 - Missing Authorization to Unauthenticated Sensitive PDF Disclosure via 'slug' Parameter5.3
- CVE-2026-57312WordPress Everest Forms plugin <= 3.4.8 - Reflected Cross Site Scripting (XSS) vulnerability7.1
- CVE-2026-1869User Registration & Membership <= 5.2.0 - Missing Authorization to Unauthenticated Payment Bypass6.5
- CVE-2026-7651User Registration & Membership <= 5.1.5 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Media Deletion via 'profile-pic-url' Parameter5.3
- CVE-2026-4888Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder <= 3.4.7 - Missing Authorization to Authenticated (Subscriber+) Email Sending4.3
- CVE-2026-6145User Registration & Membership <= 5.1.5 - Unauthenticated Missing Authorization to Admin Approval Bypass via 'action' Parameter5.3
- CVE-2026-3601User Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Limited Page Content Modification4.3
- CVE-2026-4882User Registration Advanced Fields <= 1.6.20 - Unauthenticated Arbitrary File Upload9.8
The record
- Peak rank
- #95 in Apr 2025
- Busiest month shown
- Apr 2025, 9 CVEs
- Months with a KEV entry
- 0 since Apr 2025
- Monthly snapshots
- 1 since 2025