Everest Forms, a popular plugin for creating forms in WordPress, has been found to contain a critical Stored Cross-Site Scripting (XSS) vulnerability, identified as CVE-2024-10471. This vulnerability allows attackers with editor-level privileges to inject malicious JavaScript code into the plugin’s form settings, which could lead to account takeover and the creation of backdoors. Given the large user base of Everest Forms, with over 6 million active installations, this vulnerability poses a significant threat to the security of many WordPress websites.
CVE-2024-10471 – Everest Forms – Stored XSS to Backdoor Creation – POC
![CVE-2024-10471 – Everest Forms – Stored XSS to Backdoor Creation – POC CVE-2024-10471 – Everest Forms – Stored XSS to Backdoor Creation – POC](https://research.cleantalk.org/wp-content/uploads/2023/10/New_1_not_safe-1.png)