Impact
The Everest Forms plugin for WordPress contains a flaw in the EVF_Form_Fields_Upload class that allows unauthenticated users to upload, read, and delete arbitrary files on the server. The lack of file type and path validation permits attackers to place malicious scripts or other files, which can lead to remote code execution, data theft, or a full site takeover. This weakness is classified as CWE-434.
Affected Systems
WordPress sites running the Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin, versions 3.0.9.4 and earlier, should be considered vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8 and an EPSS score of 26%. Based on the description, it is inferred that this EPSS score suggests that exploitation is relatively likely. It is not listed in the CISA KEV catalog. Attackers can target the exposed upload endpoint without authentication, making exploitation straightforward over the web.
OpenCVE Enrichment
EUVD