
Cloud Vulnerability DB
A community-led vulnerabilities database
An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability was discovered in Everest Forms WordPress plugin versions before 2.0.8. The vulnerability exists in the 'font_url' parameter, allowing unauthenticated attackers to make web requests to arbitrary locations originating from the vulnerable server (WPScan).
The vulnerability is classified as a Server-Side Request Forgery (SSRF) issue that affects the font_url parameter handling in Everest Forms. This security flaw enables unauthenticated attackers to initiate server-side requests to arbitrary destinations, potentially bypassing security controls (NVD).
The vulnerability allows attackers to make unauthorized web requests from the affected server, which could potentially lead to internal network scanning, data exfiltration, or bypassing network security controls (WPScan).
The vulnerability can be exploited by unauthenticated attackers, making it particularly concerning as no authentication is required to execute the attack (NVD).
Users are advised to update to Everest Forms version 2.0.8 or later, which contains the fix for this vulnerability (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."