CVE Tools

Wpeverest

9 CVEs tracked since 2025. Since Apr 2025, none of them reached CISA KEV.

Wpeverest CVEs per month

Apr 2025 to Apr 2025. Point at a month, or focus the strip and use the arrow keys.
Wpeverest CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-0490

Products

The products that kept showing up in Wpeverest's monthly top three, with their CVEs summed over those months.

  1. User Registration \& Membership51 month
  2. Everest Forms31 month
  3. Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder31 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Wpeverest.

  1. CVE-2026-74017WordPress User Registration plugin <= 5.2.7 - Broken Access Control vulnerability5.3
  2. CVE-2026-62103WordPress Everest Forms plugin <= 3.6.0 - PHP Object Injection vulnerability9.8
  3. CVE-2026-5096Everest Forms <= 3.4.4 - Unauthenticated Server-Side Request Forgery via Upload Field 'Previous Value'5.3
  4. CVE-2026-74001WordPress User Registration & Membership Pro plugin <= 5.4.5 - Account Takeover vulnerability9.8
  5. CVE-2026-73995WordPress User Registration plugin <= 5.2.6 - Broken Authentication vulnerability5.4
  6. CVE-2026-13167Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI <= 3.5.2 - Missing Authorization to Authenticated (Delegated+) Arbitrary Plugin Activation via REST API and AJAX Endpoints4.3
  7. CVE-2026-73403WordPress User Registration plugin <= 5.2.6 - Broken Access Control vulnerability5.3
  8. CVE-2026-12124PDFDraft <= 1.1.0 - Missing Authorization to Unauthenticated Sensitive PDF Disclosure via 'slug' Parameter5.3
  9. CVE-2026-57312WordPress Everest Forms plugin <= 3.4.8 - Reflected Cross Site Scripting (XSS) vulnerability7.1
  10. CVE-2026-1869User Registration & Membership <= 5.2.0 - Missing Authorization to Unauthenticated Payment Bypass6.5
  11. CVE-2026-7651User Registration & Membership <= 5.1.5 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Media Deletion via 'profile-pic-url' Parameter5.3
  12. CVE-2026-4888Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder <= 3.4.7 - Missing Authorization to Authenticated (Subscriber+) Email Sending4.3
  13. CVE-2026-6145User Registration & Membership <= 5.1.5 - Unauthenticated Missing Authorization to Admin Approval Bypass via 'action' Parameter5.3
  14. CVE-2026-3601User Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Limited Page Content Modification4.3
  15. CVE-2026-4882User Registration Advanced Fields <= 1.6.20 - Unauthenticated Arbitrary File Upload9.8

The record

Peak rank
#95 in Apr 2025
Busiest month shown
Apr 2025, 9 CVEs
Months with a KEV entry
0 since Apr 2025
Monthly snapshots
1 since 2025
Wpeverest's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store