CVE-2026-11571 Details
Description
The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users' form submission records via predictable, enumerable filenames.
A vulnerability exists in the Everest Forms WordPress plugin in versions prior to 3.5.0, where temporary CSV files created during email notification processing are not consistently deleted. These files are left publicly accessible in the uploads directory, allowing unauthenticated attackers to access other users' form submission records through predictable, enumerable filenames. Exploitation requires the Everest Forms Pro add-on to be active, as the CSV email attachment feature is only available with Pro. The vulnerability arises when a form has multiple email notifications, with the CSV attachment enabled on a notification that is processed before the one where it is disabled. In such cases, the entry identifiers, which are sequential and returned to the submitter in the response, can be easily enumerated to retrieve the exposed CSV files.
Users are advised to update the Everest Forms WordPress plugin to version 3.5.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 9, 2026CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/4bd381e9-2f4e-4e61-99af-88f50aed71f5/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Everest Forms | < 3.5.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |
Volerion