Executive brief
Everest Forms is a popular WordPress plugin used to create contact and registration forms. A security flaw in versions prior to 3.5.0 fails to delete temporary files containing form submission data, leaving them publicly accessible on the web server. This allows unauthorized individuals to download and view sensitive information submitted by other users, such as names, email addresses, and private messages, by guessing simple file names.
Technical details
A sensitive information disclosure vulnerability exists in Everest Forms (specifically when the Pro add-on is active) due to improper cleanup of temporary artifacts. When a form is configured with multiple email notifications and a CSV attachment is enabled on a notification that is not the last one processed, the plugin fails to delete the generated CSV file from the '/uploads/Everes-Froms-Entries-CSV-file/' directory. Because form entry IDs are sequential and disclosed in the submission response, unauthenticated attackers can enumerate and download these CSV files. The issue is fixed in version 3.5.0.
Affected products
- WPEverest Everest Forms < 3.5.0
Timeline
- 2026-06-18: disclosed: Publicly published by WPScan
- 2026-07-09: advisory: CVE published to NVD dataset