Impact
The Everest Forms WordPress plugin before version 3.5.0 fails to reliably delete temporary CSV files created during email‑notification processing. As a result, these files remain in the public uploads directory and can be retrieved by anyone. An unauthenticated attacker who knows the predictable file names can download other users’ form submission records, causing a confidentiality breach. This vulnerability represents an instance of information exposure, matching CWE-200, and also reflects improper access control, matching CWE-284.
Affected Systems
WordPress sites that have the Everest Forms plugin installed with a version earlier than 3.5.0 are affected. The plugin is identified only as Everest Forms, and all releases before 3.5.0 are vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates substantial confidentiality risk. Because the temporary CSV files are left in a publicly accessible uploads directory, an attacker only needs to know the predictable filename pattern to download them, which requires no authentication. The EPSS score of less than 1 % suggests that exploitation attempts are relatively rare, but the simplicity of the attack makes it possible. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment