
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22422 is an Improper Neutralization of Script-Related HTML Tags (Basic XSS) vulnerability in the Everest Forms WordPress plugin by wpeverest, classified under CWE-80. The flaw allows unauthenticated attackers to inject script-related HTML tags into web pages, enabling code injection. It affects Everest Forms versions up to and including 3.4.1. The vulnerability was published on February 19, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (Feedly).
The root cause is improper neutralization of script-related HTML tags in web page output (CWE-80), which is a form of reflected or stored XSS that targets non-script HTML elements. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by any remote attacker. The vulnerability is associated with CAPEC attack patterns including XSS Targeting Non-Script Elements (CAPEC-18), XSS Through HTTP Query Strings (CAPEC-32), and XSS Through HTTP Headers (CAPEC-86), suggesting the injection point may be in form fields or HTTP parameters processed by the plugin (Feedly).
Successful exploitation results in a low integrity impact with no confidentiality or availability impact, as reflected in the CVSS score. An attacker could inject malicious HTML or script-related tags into pages rendered by the Everest Forms plugin, potentially leading to code injection in the context of the affected web page. While the direct impact is limited, this could be leveraged to manipulate page content, perform phishing, or escalate to more severe attacks depending on the site's configuration (Feedly).
The vulnerability requires no privileges and no user interaction, making it accessible to unauthenticated remote attackers with low complexity. The EPSS score is approximately 0.029% (0.000290), indicating a currently low probability of exploitation in the wild. No evidence of active in-the-wild exploitation, exploit kits, or threat actor attribution has been reported at this time, and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog (Feedly).
Users should update the Everest Forms WordPress plugin to a version beyond 3.4.1, as all versions up to and including 3.4.1 are affected. Site administrators should check the WordPress plugin dashboard for available updates and apply them promptly. As a temporary workaround, consider disabling the Everest Forms plugin until a patched version is available, or implement a web application firewall (WAF) rule to filter script-related HTML tags in form inputs (Feedly, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."