CVE-2024-1812

The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.


We have discovered 12,472 live websites that are affected by CVE-2024-1812.

Test my site




Affected Software

Product  Everest Forms
Category Wordpress Plugins
Vulnerable Domains12,472 live websites (47.49% of Everest Forms install base)
Vulnerable Versions
  • from 0 through 2.0.7
Vulnerable Versions Count105 versions ( 80.77% of all versions)



Details

  • Published - Apr 9, 2024
  • Updated - Aug 1, 2024

Credits

  • hoangnd123123 (finder)

CVE-2024-1812 usage by Country

United States3,098 websites



Germany1,559 websites
France857 websites
Brazil541 websites
Poland485 websites
GB444 websites
Russia429 websites
Turkey378 websites
Netherlands327 websites
Italy303 websites

CVE-2024-1812 usage by TLD

.com4,511 websites
.de715 websites
.org573 websites
.ru464 websites
.pl401 websites
.com.br367 websites
.net337 websites
.nl328 websites
.fr279 websites
.co.uk254 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-1812

Top websites that are affected by CVE-2024-1812. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.org United States**,***
********.com United States**,***
*****.***.br Brazil**,***
**************************.com Germany***,***
****.org United States***,***
**********.com United States***,***
***************.org United States***,***
*******.org United States***,***
******.com United States***,***
************.com Australia***,***
See full domain list

FAQ

A total of 12,472 websites have been identified as vulnerable to CVE-2024-1812, discovered through global website indexing conducted by WebTechSurvey.
Everest Forms is susceptible to CVE-2024-1812 vulnerability.
Everest Forms versions before, and including, 2.0.7 are vulnerable to CVE-2024-1812.