Junglewise Threat Intelligence

CVE-2026-4888: WPEverest Everest Forms unauthorized email sending in send_test_email

CVE-2026-4888 · Severity: medium · CVSS 4.3 · Published 2026-05-28

Technologies: WPEverest Everest Forms. Vendors: WPEverest.

Executive brief

Everest Forms, a popular WordPress plugin used for creating contact and payment forms, contains a security flaw that allows unauthorized users to send emails from the website's server. An attacker with basic login credentials, such as a subscriber, can exploit this to send test emails to any email address. While this does not directly expose sensitive data, it can be used to damage the organization's reputation or facilitate phishing campaigns by sending emails that appear to originate from a trusted corporate domain.

Technical details

The vulnerability is classified as Missing Authorization (CWE-862) within the send_test_email() function located in the class-evf-ajax.php file. The plugin fails to perform a capability check to verify if the user has administrative privileges before executing the AJAX action. Consequently, any authenticated user with at least Subscriber-level permissions can trigger the function to send emails to arbitrary recipients from the server. This can lead to email spoofing or the use of the server as an open relay for spam. The issue is present in all versions up to and including 3.4.7.

Affected products

  • WPEverest Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder Up to and including 3.4.7

Timeline

  • 2026-05-27: disclosed: Initial disclosure by Wordfence
  • 2026-05-28: advisory: NVD publication date

References

Related threats