SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  WordPress plugin Everest Forms Remote Code Execution

Category: WEB-ATTACKS      

The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_filter() function concatenating user-submitted form field values into a PHP code string without proper escaping before passing it to eval().


Relevant Information