PT-2026-56701 · WordPress · Everest Forms
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Everest Forms WordPress plugin versions prior to 3.5.0
Description
Insufficient access restrictions in the onboarding assistant's REST API endpoints allow unauthenticated attackers to bypass capability checks. This bypass occurs because the check is only triggered when a specific value is present in a request header; omitting or modifying this header allows unauthorized access. Consequently, attackers can read onboarding status information, modify plugin options, and trigger emails from the site to arbitrary addresses.
Recommendations
Update Everest Forms WordPress plugin to version 3.5.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Everest Forms