Description
The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with delegated form management access and above, to activate arbitrary already-installed WordPress plugins — including previously deactivated or vulnerable plugins — without holding the core activate_plugins capability. Exploitation requires the target user to hold a delegated Everest Forms capability (manage_everest_forms, everest_forms_create_forms, or everest_forms_view_forms), which the plugin's own roles and permissions tool allows administrators to assign to non-administrator roles such as Author; the nonces required to exploit the AJAX handlers are emitted on EVF admin pages accessible to any such delegated user.
Published: 2026-08-16
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Everest Forms plugin for WordPress contains a missing authorization check that permits authenticated users with delegated Everest Forms management rights to activate any existing WordPress plugin without possessing the core activate_plugins capability. This flaw effectively provides a privilege escalation path for attackers who can reach forms management features, allowing them to enable malicious or vulnerable plugins and potentially compromise site integrity.

Affected Systems

All installations of the Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin, versions up to and including 3.5.2, regardless of the underlying WordPress version.

Risk and Exploitability

The vulnerability carries a CVSS score of 4.3, indicating moderate severity, and no EPSS score is available. It is not listed in the CISA KEV catalog. Effective exploitation requires the attacker to be an authenticated user holding at least one delegated Everest Forms capability (such as manage_everest_forms, everest_forms_create_forms, or everest_forms_view_forms) and to interact with the plugin’s AJAX or REST API endpoints, which emit nonces on admin pages accessible to such users. The attack vector is therefore internal but does not require elevated WordPress roles, making the threat moderate within environments where non-admin roles have been granted Everest Forms privileges.

Generated by OpenCVE AI on August 16, 2026 at 06:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Everest Forms to the latest release that fixes the missing authorization check (any version after 3.5.2)
  • Revoke delegated Everest Forms capabilities from all non-administrator roles so that only administrators can manage forms
  • Audit the list of active plugins and deactivate any that were enabled without permission

Generated by OpenCVE AI on August 16, 2026 at 06:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 16 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Description The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with delegated form management access and above, to activate arbitrary already-installed WordPress plugins — including previously deactivated or vulnerable plugins — without holding the core activate_plugins capability. Exploitation requires the target user to hold a delegated Everest Forms capability (manage_everest_forms, everest_forms_create_forms, or everest_forms_view_forms), which the plugin's own roles and permissions tool allows administrators to assign to non-administrator roles such as Author; the nonces required to exploit the AJAX handlers are emitted on EVF admin pages accessible to any such delegated user.
Title Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI <= 3.5.2 - Missing Authorization to Authenticated (Delegated+) Arbitrary Plugin Activation via REST API and AJAX Endpoints
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-16T04:24:54.079Z

Reserved: 2026-06-24T13:20:44.511Z

Link: CVE-2026-13167

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-16T05:16:46.077

Modified: 2026-08-16T05:16:46.077

Link: CVE-2026-13167

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-16T06:30:04Z

Weaknesses