Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Everest Forms allows Reflected XSS.

This issue affects Everest Forms: from n/a through 3.6.1.
Published: 2026-10-07
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross‑site scripting (XSS) that can execute arbitrary scripts in the victim’s browser
Action: Immediate Patch
AI Analysis

Impact

Improper neutralization of input during web page generation allows attackers to inject malicious JavaScript into pages rendered by the Everest Forms plugin. The reflected XSS flaw can be used to steal cookies, hijack user sessions, deface content, or perform other client‑side attacks, impacting confidentiality, integrity, and availability of the user’s data.

Affected Systems

The vulnerability exists in the Everest Forms WordPress plugin in all releases from its initial launch through version 3.6.1. Systems running any of those versions are affected.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium severity flaw. EPSS information is not published, and the issue is not listed in CISA’s KEV catalog. The attacker can exploit the flaw by submitting crafted input in a form or URI that is then reflected in the page, requiring no authentication. Attackers host malicious code within the reflected payload and supply it to unsuspecting users who view the affected page, enabling client‑side compromise.

Generated by OpenCVE AI on October 7, 2026 at 18:33 UTC.

Remediation

Vendor Solution

Update the WordPress Everest Forms Plugin to the latest available version (at least 3.6.2).


OpenCVE Recommended Actions

  • Upgrade the Everest Forms plugin to version 3.6.2 or later.
  • If an upgrade cannot be performed immediately, disable or remove the plugin until the patch is applied.
  • Implement a strict Content Security Policy to reduce the impact of any remaining XSS vectors.

Generated by OpenCVE AI on October 7, 2026 at 18:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Everest Forms allows Reflected XSS. This issue affects Everest Forms: from n/a through 3.6.1.
Title WordPress Everest Forms plugin <= 3.6.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-07T19:23:46.278Z

Reserved: 2026-09-22T00:19:50.791Z

Link: CVE-2026-94670

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T17:17:03.643

Modified: 2026-10-07T17:17:03.643

Link: CVE-2026-94670

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T18:45:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')