Impact
The Everest Forms plugin for WordPress contains a missing authorization check that permits authenticated users with delegated Everest Forms management rights to activate any existing WordPress plugin without possessing the core activate_plugins capability. This flaw effectively provides a privilege escalation path for attackers who can reach forms management features, allowing them to enable malicious or vulnerable plugins and potentially compromise site integrity.
Affected Systems
All installations of the Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin, versions up to and including 3.5.2, regardless of the underlying WordPress version.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.3, indicating moderate severity, and no EPSS score is available. It is not listed in the CISA KEV catalog. Effective exploitation requires the attacker to be an authenticated user holding at least one delegated Everest Forms capability (such as manage_everest_forms, everest_forms_create_forms, or everest_forms_view_forms) and to interact with the plugin’s AJAX or REST API endpoints, which emit nonces on admin pages accessible to such users. The attack vector is therefore internal but does not require elevated WordPress roles, making the threat moderate within environments where non-admin roles have been granted Everest Forms privileges.
OpenCVE Enrichment