Vulnerability Intelligence Report
Everest Forms <= 2.0.7 - Unauthenticated Server-Side Request Forgery via font_url
CVE-2024-1812
The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
No Active Exploit Signals
CVSS Base Score
7.2
HIGH
Exploitability:3.9
Impact Score:2.8
EPSS Probability:0.54%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-918 ↗CWE-918 Server-Side Request Forgery (SSRF)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| wpeverest | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder | 0 <= 2.0.7 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.536%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Wordfence · Vendor · USA |
| Reserved | 2024-02-22T22:43:10 |
| Published | 2024-04-09T18:59:24 |
| Last Updated | 2026-04-08T17:25:48 |
Community Chatter & Buzz