CVE-2026-11571: Everest Forms < 3.5.0 - Unauthenticated Sensitive Information Exposure via Residual CSV Artifacts
The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users' form submission records via predictable, enumerable filenames.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11571?
CVE-2026-11571 has a high severity rating of 7.5 on the CVSS scale.
How do I fix CVE-2026-11571?
To fix CVE-2026-11571, upgrade the Everest Forms WordPress plugin to version 3.5.0 or later.
What kind of information is exposed by CVE-2026-11571?
CVE-2026-11571 exposes sensitive user form submission records through publicly accessible temporary CSV files.
Who is affected by CVE-2026-11571?
Users of versions of the Everest Forms WordPress plugin prior to 3.5.0 are affected by CVE-2026-11571.
Can unauthenticated attackers exploit CVE-2026-11571?
Yes, unauthenticated attackers can exploit CVE-2026-11571 to access sensitive information.