AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-11571

HIGH · CVSS 7.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

The Everest Forms WordPress plugin prior to version 3.5.0 is vulnerable due to improper deletion of temporary CSV files, which remain publicly accessible in the uploads directory. This flaw allows unauthenticated attackers to exploit predictable filenames to access sensitive form submission records from other users. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of data exposure.

CVE
CVE-2026-11571
Severity
HIGH
CVSS
7.5
EPSS
0.26%
WordPress

Original NVD Description

The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users' form submission records via predictable, enumerable filenames.