PT-2025-16115 · WordPress · Everest Forms

·

CVE-2025-3422

·

Published

2025-04-11

·

Updated

2025-04-23

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress versions up to 3.1.1
Description: The issue arises from the software's failure to properly validate a value before executing do shortcode, allowing authenticated attackers with Subscriber-level access or higher to execute arbitrary shortcodes. This can be exploited by attackers to execute actions that are not intended by the software.
Recommendations: For versions up to 3.1.1, update to a version higher than 3.1.1 to resolve the issue. As a temporary workaround, consider restricting access to the do shortcode function to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-3422

Affected Products

Everest Forms