Everest Forms is a popular WordPress plugin that allows users to create and manage forms for collecting user information, including contact forms, surveys, and registration forms. A critical Stored Cross-Site Scripting (XSS) vulnerability, identified as CVE-2024-13125, has been found in the plugin. This vulnerability allows attackers with editor-level access to inject malicious JavaScript into the “Email Message” field in the Email Template settings. The injected script is then executed when the email template is previewed, allowing attackers to hijack the session of an admin user or escalate their privileges to gain full control of the WordPress site. With over 100,000 active installations, this vulnerability poses a significant security risk for websites using Everest Forms.
CVE-2024-13125 – Everest Forms – Stored XSS to JS Backdoor Creation – POC
