WordPress · Everest Forms · CVE-2026-57312
**Name of the Vulnerable Software and Affected Versions**
Everest Forms versions prior to 3.4.9
**Description**
An unauthenticated Cross Site Scripting (XSS) issue exists, which allows an attacker to execute malicious scripts in the browser of a user without requiring prior authentication.
**Recommendations**
Update to a version newer than 3.4.8.