WordPress · Everest Forms · CVE-2026-13167
**Name of the Vulnerable Software and Affected Versions**
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI versions prior to 3.5.3
**Description**
An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Authenticated attackers with delegated form management access can activate any already-installed WordPress plugins, including those previously deactivated or known to be vulnerable, without possessing the core `activate plugins` capability. This exploitation is possible for users assigned delegated capabilities such as `manage everest forms`, `everest forms create forms`, or `everest forms view forms`. The process involves using nonces emitted on admin pages accessible to these delegated users to interact with AJAX handlers.
**Recommendations**
Update to a version newer than 3.5.2.