Executive brief
Everest Forms is a popular WordPress plugin for creating web forms. The plugin contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to trick the WordPress server into making HTTP requests to arbitrary external URLs by submitting a specially crafted form. This could enable attackers to access internal network resources, scan the internal network, or bypass firewall restrictions.
Technical details
The vulnerability is a Server-Side Request Forgery (SSRF) flaw in the `load_previous_field_value()` method of `class-evf-form-task.php`. The method accepts arbitrary URL values from POST data for upload fields without domain validation, which are then passed to `wp_remote_head()` in the `get_local_file_size()` method of `class-evf-form-fields-upload.php`. An unauthenticated attacker can exploit this by submitting a form with an upload field containing a malicious URL while leaving a required field empty to trigger form re-rendering. This forces the WordPress server to make outbound HTTP HEAD requests to arbitrary URLs, potentially exposing internal network information or enabling interaction with internal services.
Affected products
- Klaus Greff Everest Forms up to and including 3.4.4
Timeline
- 2026-08-28: disclosed