The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
We have discovered 12,472 live websites that are affected by CVE-2024-1812.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 12,472 live websites (47.49% of Everest Forms install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 105 versions ( 80.77% of all versions) |
![]() | 3,098 websites |
![]() | 1,559 websites |
![]() | 857 websites |
![]() | 541 websites |
![]() | 485 websites |
![]() | 444 websites |
![]() | 429 websites |
![]() | 378 websites |
![]() | 327 websites |
![]() | 303 websites |
.com | 4,511 websites |
.de | 715 websites |
.org | 573 websites |
.ru | 464 websites |
.pl | 401 websites |
.com.br | 367 websites |
.net | 337 websites |
.nl | 328 websites |
.fr | 279 websites |
.co.uk | 254 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
************.org | ![]() | **,*** | |
********.com | ![]() | **,*** | |
*****.***.br | ![]() | **,*** | |
**************************.com | ![]() | ***,*** | |
****.org | ![]() | ***,*** | |
**********.com | ![]() | ***,*** | |
***************.org | ![]() | ***,*** | |
*******.org | ![]() | ***,*** | |
******.com | ![]() | ***,*** | |
************.com | ![]() | ***,*** |
FAQ