Impact
Improper neutralization of input during web page generation allows attackers to inject malicious JavaScript into pages rendered by the Everest Forms plugin. The reflected XSS flaw can be used to steal cookies, hijack user sessions, deface content, or perform other client‑side attacks, impacting confidentiality, integrity, and availability of the user’s data.
Affected Systems
The vulnerability exists in the Everest Forms WordPress plugin in all releases from its initial launch through version 3.6.1. Systems running any of those versions are affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium severity flaw. EPSS information is not published, and the issue is not listed in CISA’s KEV catalog. The attacker can exploit the flaw by submitting crafted input in a form or URI that is then reflected in the page, requiring no authentication. Attackers host malicious code within the reflected payload and supply it to unsuspecting users who view the affected page, enabling client‑side compromise.
OpenCVE Enrichment