Junglewise Threat Intelligence

CVE-2026-12270: WPEverest Everest Forms missing authorization in Site Assistant REST API

CVE-2026-12270 · Severity: info · CVSS 5.3 · Published 2026-07-09

Technologies: WPEverest Everest Forms. Vendors: WPEverest.

Executive brief

Everest Forms, a popular WordPress plugin used for creating contact forms, contains a security flaw in its onboarding assistant. This vulnerability allows unauthorized individuals to bypass security checks by manipulating or omitting specific web request headers. As a result, an attacker could view internal setup status, change certain plugin settings, or use the website to send emails to arbitrary addresses, potentially damaging the site's reputation or disrupting its configuration.

Technical details

The Everest Forms plugin before version 3.5.0 contains a missing authorization vulnerability within its Site Assistant REST API endpoints. The root cause is an improper capability check that is only triggered if a specific 'Referer' header is present in the request; by omitting or modifying this header, unauthenticated attackers can bypass the check entirely. Exploitation allows remote, unauthenticated attackers to read onboarding status, modify plugin options (such as skipping spam protection setup), and trigger the 'test-email' functionality to send emails from the host server to any arbitrary address. The issue is fixed in version 3.5.0.

Affected products

  • WPEverest Everest Forms < 3.5.0

Timeline

  • 2026-06-18: disclosed: Publicly published via WPScan
  • 2026-07-09: advisory: NVD publication date
  • 2026-07-09: patched: Fixed in version 3.5.0

References

Related threats