Junglewise Threat Intelligence

CVE-2026-5096: Everest Forms Server-Side Request Forgery in upload handling

CVE-2026-5096 · Severity: medium · CVSS 5.3 · Published 2026-08-28

Technologies: Klaus Greff Everest Forms.

Executive brief

Everest Forms is a popular WordPress plugin for creating web forms. The plugin contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to trick the WordPress server into making HTTP requests to arbitrary external URLs by submitting a specially crafted form. This could enable attackers to access internal network resources, scan the internal network, or bypass firewall restrictions.

Technical details

The vulnerability is a Server-Side Request Forgery (SSRF) flaw in the `load_previous_field_value()` method of `class-evf-form-task.php`. The method accepts arbitrary URL values from POST data for upload fields without domain validation, which are then passed to `wp_remote_head()` in the `get_local_file_size()` method of `class-evf-form-fields-upload.php`. An unauthenticated attacker can exploit this by submitting a form with an upload field containing a malicious URL while leaving a required field empty to trigger form re-rendering. This forces the WordPress server to make outbound HTTP HEAD requests to arbitrary URLs, potentially exposing internal network information or enabling interaction with internal services.

Affected products

  • Klaus Greff Everest Forms up to and including 3.4.4

Timeline

  • 2026-08-28: disclosed

References