CVE-2026-5096: Everest Forms <= 3.4.4 - Unauthenticated Server-Side Request Forgery via Upload Field 'Previous Value'

Published Aug 28, 2026
·
Updated

The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the loadpreviousfieldvalue() method in class-evf-form-task.php accepting arbitrary URL values from $POST data for upload fields without domain restriction, which are then passed to wpremotehead() in the getlocalfilesize() method of class-evf-form-fields-upload.php. This makes it possible for unauthenticated attackers to force the WordPress server to make outbound HTTP HEAD requests to arbitrary URLs by submitting a form with an upload field containing a malicious URL while leaving a required field empty to trigger form re-rendering.

Affected Software

1 affected component
Everest Forms Everest Forms (WordPress plugin)<=3.4.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Everest Forms (WordPress plugin) to a version that resolves this vulnerability.

    Fixed in 3.4.4
  2. Compensating control

    As a compensating control until patched, restrict outbound HTTP(S) traffic from the WordPress server (e.g., via firewall/egress rules) so wp_remote_head() cannot reach arbitrary external URLs.

Event History

Aug 28, 2026
CVE Published
via MITRE·11:29 AM
Data Sourced
via MITRE·11:29 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What conditions must be present for an attacker to exploit this issue?

The site must expose an Everest Forms form containing an upload field. An unauthenticated attacker can submit that form with a malicious URL as the upload field's previous value and leave a required field empty so the form is re-rendered.

2

What can an attacker make the affected server do?

An attacker can cause the WordPress server to send outbound HTTP HEAD requests to arbitrary URLs. The described impact is limited to server-side requests; no integrity or availability impact is stated.

3

Are sites using the affected plugin exposed by default?

Exposure depends on whether an Everest Forms form with an upload field is available for submission. The described attack does not require authentication, but it relies on being able to submit such a form and trigger validation failure through an empty required field.

4

Which plugin versions are affected?

Everest Forms versions up to and including 3.4.4 are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203