CVE-2024-1812

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-1812
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-1812.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-1812
Published
2024-04-09T19:15:19Z
Modified
2025-05-17T14:04:05.314013Z
Summary
[none]
Details

The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

References

Affected packages

Git / github.com/wpeverest/everest-forms

Affected ranges

Type
GIT
Repo
https://github.com/wpeverest/everest-forms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.0-rc.1
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.5.1
1.2.0
1.2.0-rc.1
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.4.0
1.4.0-beta
1.4.0-beta2
1.4.0-beta3
1.4.0-beta4
1.4.0-beta5
1.4.0-beta6
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.4.8
1.4.9
1.5.0
1.5.1
1.5.10
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.6.1
1.6.7
1.7.0
1.7.0.1
1.7.0.2
1.7.0.3
1.7.1
1.7.2
1.7.2.1
1.7.2.2
1.7.3
1.7.4
1.7.5
1.7.5.1
1.7.5.2
1.7.6
1.7.7
1.7.7.1
1.7.7.2
1.7.8
1.7.9
1.8.0
1.8.0.1
1.8.1
1.8.2
1.8.2.1
1.8.2.2
1.8.2.3
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.8.8
1.8.9
1.9.0
1.9.0.1
1.9.1
1.9.2
1.9.3
1.9.4
1.9.4.1
1.9.5
1.9.6
1.9.7
1.9.8
1.9.9

2.*

2.0.0
2.0.0.1
2.0.1
2.0.2
2.0.3
2.0.3.1
2.0.4
2.0.4.1
2.0.5
2.0.6
2.0.7

v1.*

v1.4.0-beta