{"schema_version":1,"title":"WPEverest vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 13 vulnerabilities in WPEverest: 0 in the last 7 days and 4 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-12124, was published on 28 July 2026. 3 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/wpeverest","json_url":"https://junglewise.ai/threats/vendors/wpeverest.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/wpeverest","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":2,"all_time":13,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":4,"last_365_days":13},"latest":[{"cve":"CVE-2026-12124","cvss":5.3,"slug":"cve-2026-12124-wpeverest-pdfdraft-missing-authorization-in-pdf-serving-functions","title":"wpeverest PDFDraft missing authorization in PDF serving functions","severity":"medium","exploited":false,"published_at":"2026-07-28T07:16:40.787+00:00","url":"https://junglewise.ai/threats/cve-2026-12124-wpeverest-pdfdraft-missing-authorization-in-pdf-serving-functions"},{"cve":"CVE-2026-12270","cvss":5.3,"slug":"cve-2026-12270-wpeverest-everest-forms-missing-authorization-in-site-assistant","title":"WPEverest Everest Forms missing authorization in Site Assistant REST API","severity":"info","exploited":false,"published_at":"2026-07-09T07:16:23.21+00:00","url":"https://junglewise.ai/threats/cve-2026-12270-wpeverest-everest-forms-missing-authorization-in-site-assistant"},{"cve":"CVE-2026-11571","cvss":5.9,"slug":"cve-2026-11571-everest-forms-information-disclosure-via-residual-csv-artifacts","title":"Everest Forms information disclosure via residual CSV artifacts","severity":"info","exploited":false,"published_at":"2026-07-09T07:16:22.847+00:00","url":"https://junglewise.ai/threats/cve-2026-11571-everest-forms-information-disclosure-via-residual-csv-artifacts"},{"cve":"CVE-2026-11965","cvss":6.5,"slug":"cve-2026-11965-wpeverest-user-registration-membership-payment-bypass-in-paid","title":"WPEverest User Registration & Membership payment bypass in paid plans","severity":"info","exploited":false,"published_at":"2026-07-02T06:16:13.39+00:00","url":"https://junglewise.ai/threats/cve-2026-11965-wpeverest-user-registration-membership-payment-bypass-in-paid"},{"cve":"CVE-2026-57312","cvss":7.1,"slug":"cve-2026-57312-wpeverest-everest-forms-unauthenticated-reflected-xss","title":"WPEverest Everest Forms unauthenticated reflected XSS","severity":"high","exploited":false,"published_at":"2026-06-26T15:16:47.563+00:00","url":"https://junglewise.ai/threats/cve-2026-57312-wpeverest-everest-forms-unauthenticated-reflected-xss"},{"cve":"CVE-2026-52701","cvss":6.5,"slug":"cve-2026-52701-themegrill-user-registration-broken-access-control","title":"ThemeGrill User Registration broken access control","severity":"medium","exploited":false,"published_at":"2026-06-26T15:16:39.72+00:00","url":"https://junglewise.ai/threats/cve-2026-52701-themegrill-user-registration-broken-access-control"},{"cve":"CVE-2026-1869","cvss":6.5,"slug":"cve-2026-1869-wpeverest-user-registration-membership-payment-bypass","title":"WPEverest User Registration & Membership payment bypass","severity":"medium","exploited":false,"published_at":"2026-06-26T09:16:34.01+00:00","url":"https://junglewise.ai/threats/cve-2026-1869-wpeverest-user-registration-membership-payment-bypass"},{"cve":"CVE-2026-25425","cvss":7.5,"slug":"cve-2026-25425-themegrill-user-registration-broken-access-control","title":"ThemeGrill User Registration broken access control","severity":"high","exploited":false,"published_at":"2026-06-15T21:16:40.283+00:00","url":"https://junglewise.ai/threats/cve-2026-25425-themegrill-user-registration-broken-access-control"},{"cve":"CVE-2026-7651","cvss":5.3,"slug":"cve-2026-7651-wpeverest-user-registration-idor-in-media-deletion","title":"WPEverest User Registration IDOR in media deletion","severity":"medium","exploited":false,"published_at":"2026-05-28T08:16:37.117+00:00","url":"https://junglewise.ai/threats/cve-2026-7651-wpeverest-user-registration-idor-in-media-deletion"},{"cve":"CVE-2026-4888","cvss":4.3,"slug":"cve-2026-4888-wpeverest-everest-forms-unauthorized-email-sending-in-send-test","title":"WPEverest Everest Forms unauthorized email sending in send_test_email","severity":"medium","exploited":false,"published_at":"2026-05-28T00:16:43.797+00:00","url":"https://junglewise.ai/threats/cve-2026-4888-wpeverest-everest-forms-unauthorized-email-sending-in-send-test"},{"cve":"CVE-2026-6145","cvss":5.3,"slug":"cve-2026-6145-wordpress-user-registration-membership-missing-authorization-in","title":"WordPress User Registration & Membership missing authorization in registration","severity":"medium","exploited":false,"published_at":"2026-05-14T09:16:26.29+00:00","url":"https://junglewise.ai/threats/cve-2026-6145-wordpress-user-registration-membership-missing-authorization-in"},{"cve":"CVE-2026-1865","cvss":6.5,"epss":0.0031,"slug":"cve-2026-1865-wpeverest-user-registration-membership-sql-injection-in-membership","title":"WPEverest User Registration & Membership SQL injection in membership_ids","severity":"medium","exploited":false,"published_at":"2026-04-08T12:16:20.44+00:00","url":"https://junglewise.ai/threats/cve-2026-1865-wpeverest-user-registration-membership-sql-injection-in-membership"},{"cve":"CVE-2026-3296","cvss":9.8,"epss":0.0347,"slug":"cve-2026-3296-wpeverest-everest-forms-php-object-injection-in-form-entry","title":"WPEverest Everest Forms PHP Object Injection in form entry metadata","severity":"critical","exploited":false,"published_at":"2026-04-08T02:16:04.067+00:00","url":"https://junglewise.ai/threats/cve-2026-3296-wpeverest-everest-forms-php-object-injection-in-form-entry"}],"vendor":{"hub":true,"name":"WPEverest","slug":"wpeverest","homepage":"https://wpeverest.com/","description":"A software developer specializing in WordPress plugins for forms and business tools.","url":"https://junglewise.ai/threats/vendors/wpeverest"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-3296","cvss":9.8,"epss":0.0347,"slug":"cve-2026-3296-wpeverest-everest-forms-php-object-injection-in-form-entry","title":"WPEverest Everest Forms PHP Object Injection in form entry metadata","severity":"critical","exploited":false,"published_at":"2026-04-08T02:16:04.067+00:00","url":"https://junglewise.ai/threats/cve-2026-3296-wpeverest-everest-forms-php-object-injection-in-form-entry"},{"cve":"CVE-2026-25425","cvss":7.5,"slug":"cve-2026-25425-themegrill-user-registration-broken-access-control","title":"ThemeGrill User Registration broken access control","severity":"high","exploited":false,"published_at":"2026-06-15T21:16:40.283+00:00","url":"https://junglewise.ai/threats/cve-2026-25425-themegrill-user-registration-broken-access-control"},{"cve":"CVE-2026-57312","cvss":7.1,"slug":"cve-2026-57312-wpeverest-everest-forms-unauthenticated-reflected-xss","title":"WPEverest Everest Forms unauthenticated reflected XSS","severity":"high","exploited":false,"published_at":"2026-06-26T15:16:47.563+00:00","url":"https://junglewise.ai/threats/cve-2026-57312-wpeverest-everest-forms-unauthenticated-reflected-xss"},{"cve":"CVE-2026-1865","cvss":6.5,"epss":0.0031,"slug":"cve-2026-1865-wpeverest-user-registration-membership-sql-injection-in-membership","title":"WPEverest User Registration & Membership SQL injection in membership_ids","severity":"medium","exploited":false,"published_at":"2026-04-08T12:16:20.44+00:00","url":"https://junglewise.ai/threats/cve-2026-1865-wpeverest-user-registration-membership-sql-injection-in-membership"},{"cve":"CVE-2026-52701","cvss":6.5,"slug":"cve-2026-52701-themegrill-user-registration-broken-access-control","title":"ThemeGrill User Registration broken access control","severity":"medium","exploited":false,"published_at":"2026-06-26T15:16:39.72+00:00","url":"https://junglewise.ai/threats/cve-2026-52701-themegrill-user-registration-broken-access-control"},{"cve":"CVE-2026-1869","cvss":6.5,"slug":"cve-2026-1869-wpeverest-user-registration-membership-payment-bypass","title":"WPEverest User Registration & Membership payment bypass","severity":"medium","exploited":false,"published_at":"2026-06-26T09:16:34.01+00:00","url":"https://junglewise.ai/threats/cve-2026-1869-wpeverest-user-registration-membership-payment-bypass"},{"cve":"CVE-2026-12124","cvss":5.3,"slug":"cve-2026-12124-wpeverest-pdfdraft-missing-authorization-in-pdf-serving-functions","title":"wpeverest PDFDraft missing authorization in PDF serving functions","severity":"medium","exploited":false,"published_at":"2026-07-28T07:16:40.787+00:00","url":"https://junglewise.ai/threats/cve-2026-12124-wpeverest-pdfdraft-missing-authorization-in-pdf-serving-functions"},{"cve":"CVE-2026-7651","cvss":5.3,"slug":"cve-2026-7651-wpeverest-user-registration-idor-in-media-deletion","title":"WPEverest User Registration IDOR in media deletion","severity":"medium","exploited":false,"published_at":"2026-05-28T08:16:37.117+00:00","url":"https://junglewise.ai/threats/cve-2026-7651-wpeverest-user-registration-idor-in-media-deletion"},{"cve":"CVE-2026-6145","cvss":5.3,"slug":"cve-2026-6145-wordpress-user-registration-membership-missing-authorization-in","title":"WordPress User Registration & Membership missing authorization in registration","severity":"medium","exploited":false,"published_at":"2026-05-14T09:16:26.29+00:00","url":"https://junglewise.ai/threats/cve-2026-6145-wordpress-user-registration-membership-missing-authorization-in"},{"cve":"CVE-2026-4888","cvss":4.3,"slug":"cve-2026-4888-wpeverest-everest-forms-unauthorized-email-sending-in-send-test","title":"WPEverest Everest Forms unauthorized email sending in send_test_email","severity":"medium","exploited":false,"published_at":"2026-05-28T00:16:43.797+00:00","url":"https://junglewise.ai/threats/cve-2026-4888-wpeverest-everest-forms-unauthorized-email-sending-in-send-test"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"WPEverest Everest Forms","slug":"everest-forms","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/everest-forms"},{"name":"WPEverest User Registration","slug":"user-registration","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/user-registration"},{"name":"WPEverest User Registration & Membership","slug":"user-registration-membership","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/user-registration-membership"}]}