Impact
The Everest Forms WordPress plugin before 3.5.0 lacks adequate access control on several REST API endpoints used by its onboarding assistant. The built‑in capability check is only applied when a client request header contains a specific value; omitting or altering that header bypasses the check. An attacker can therefore read the plugin’s onboarding status, change its configuration options, and trigger outbound emails to any address without authentication. The weakness is a classic authorization failure (CWE‑284).
Affected Systems
All WordPress installations that use Everest Forms version 3.4.x or earlier are affected. No other vendors or products are listed, so the impact is confined to sites that have not upgraded below the vulnerable plugin revision.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score below 1% and absence from the CISA KEV catalog suggest limited evidence of real‑world exploitation today. Nonetheless, the flaw can be exploited remotely by sending unauthenticated HTTP requests to the exposed REST routes, with no special prerequisites beyond network connectivity. Once accessed, an attacker can read sensitive configuration data, modify plugin settings, and send unsolicited emails, potentially facilitating phishing or spam campaigns.
OpenCVE Enrichment