CVE-2026-22422
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-22422 is an Improper Neutralization of Script-Related HTML Tags (Basic XSS) vulnerability in the Everest Forms WordPress plugin by wpeverest, classified under CWE-80. The flaw allows unauthenticated attackers to inject script-related HTML tags into web pages, enabling code injection. It affects Everest Forms versions up to and including 3.4.1. The vulnerability was published on February 19, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (Feedly).

Technical details

The root cause is improper neutralization of script-related HTML tags in web page output (CWE-80), which is a form of reflected or stored XSS that targets non-script HTML elements. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by any remote attacker. The vulnerability is associated with CAPEC attack patterns including XSS Targeting Non-Script Elements (CAPEC-18), XSS Through HTTP Query Strings (CAPEC-32), and XSS Through HTTP Headers (CAPEC-86), suggesting the injection point may be in form fields or HTTP parameters processed by the plugin (Feedly).

Impact

Successful exploitation results in a low integrity impact with no confidentiality or availability impact, as reflected in the CVSS score. An attacker could inject malicious HTML or script-related tags into pages rendered by the Everest Forms plugin, potentially leading to code injection in the context of the affected web page. While the direct impact is limited, this could be leveraged to manipulate page content, perform phishing, or escalate to more severe attacks depending on the site's configuration (Feedly).

Exploitability

The vulnerability requires no privileges and no user interaction, making it accessible to unauthenticated remote attackers with low complexity. The EPSS score is approximately 0.029% (0.000290), indicating a currently low probability of exploitation in the wild. No evidence of active in-the-wild exploitation, exploit kits, or threat actor attribution has been reported at this time, and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog (Feedly).

Mitigation and workarounds

Users should update the Everest Forms WordPress plugin to a version beyond 3.4.1, as all versions up to and including 3.4.1 are affected. Site administrators should check the WordPress plugin dashboard for available updates and apply them promptly. As a temporary workaround, consider disabling the Everest Forms plugin until a patched version is available, or implement a web application firewall (WAF) rule to filter script-related HTML tags in form inputs (Feedly, Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management