CyberRota Analysis
AI-GeneratedThe Everest Forms WordPress plugin prior to version 3.5.0 is vulnerable due to improper deletion of temporary CSV files, which remain publicly accessible in the uploads directory. This flaw allows unauthenticated attackers to exploit predictable filenames to access sensitive form submission records from other users. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of data exposure.
Original NVD Description
The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users' form submission records via predictable, enumerable filenames.