CVE-2026-94670: WordPress Everest Forms plugin <= 3.6.1 - Cross Site Scripting (XSS) vulnerability
Published Oct 7, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Everest Forms allows Reflected XSS.
This issue affects Everest Forms: from n/a through 3.6.1.
Affected Software
1 affected component
Everest Forms Everest Forms<=3.6.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Everest Forms Pluginto a version that resolves this vulnerability.Fixed in 3.6.2
Event History
Oct 7, 2026
CVE Published
via MITRE·04:57 PM
Data Sourced
via MITRE·04:57 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an authenticated WordPress account or victim interaction?
The supplied CVSS vector indicates no privileges are required (PR:N), but user interaction is required (UI:R). The attack vector is network-based (AV:N).
2
Is a patched release or temporary mitigation identified?
The provided data identifies affected Everest Forms versions through 3.6.1, but does not identify a fixed version or any temporary mitigation.