Impact
The vulnerability is a stored cross‑site scripting flaw in the Everest Forms Pro plugin that allows malicious input submitted through its forms to be saved and later displayed without proper neutralization. When a page rendering this stored data is viewed, the injected script executes in the victim’s browser, potentially enabling credential theft, session hijacking, defacement, or other browser‑based attacks. The flaw results from improper input neutralization during page generation and affects all WordPress sites with Everest Forms Pro version 1.9.12 or earlier.
Affected Systems
All WordPress installations that have the Everest Forms Pro plugin with a version of 1.9.12 or earlier are affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity issue. The EPSS score of 0.00039 (<1%) indicates low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path involves a user (or attacker with form submission access) submitting malicious data via the plugin’s form; this input is stored and later displayed, causing XSS. Exploitation does not appear to require privileged access beyond the existence of the plugin and the ability to submit form data.
OpenCVE Enrichment