PatchSiren

Everest Forms CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Everest Forms CVE published 2026-10-07

CVE-2026-94670

The CVE-2026-94670 vulnerability in the Everest Forms plugin for WordPress allows attackers to inject malicious scripts into web pages, potentially leading to security incidents. This Cross Site Scripting (XSS) vulnerability affects versions up to 3.6.1 and is fixed in version 3.6.2. Defenders responsible for WordPress deployments using the Everest Forms plugin should assess exposure and prioritize updati [truncated]