CVE-2025-26841: Wpeverest Everest Forms

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Cross Site Scripting vulnerability in WPEVEREST Everest Forms before 3.0.9 allows an attacker to execute arbitrary code via a file upload.

Affected products

  • Wpeverest Everest Forms: before 3.0.9 (fixed in 3.0.9)

Published 2025-05-12. Last modified 2026-06-17.