PT-2026-26281 · Wpeverest · Everest Forms Pro

Published

2026-03-19

·

Updated

2026-03-19

·

CVE-2026-27070

CVSS v3.1

7.1

High

AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Everest Forms Pro allows Stored XSS.This issue affects Everest Forms Pro: from n/a through 1.9.10.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-27070

Affected Products

Everest Forms Pro