The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.2. This…
Medium CVSS 4.3
Summary
The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with delegated form management access and above, to activate arbitrary already-installed WordPress plugins — including previously deactivated or vulnerable…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://plugins.trac.wordpress.org/browser/everest-forms/tags/3.4.5/includes/RestApi/controllers/version1/class-evf-modules.php#L315
- https://plugins.trac.wordpress.org/browser/everest-forms/tags/3.4.5/includes/RestApi/controllers/version1/class-evf-modules.php#L730
- https://plugins.trac.wordpress.org/browser/everest-forms/tags/3.4.5/includes/class-evf-ajax.php#L121
- https://plugins.trac.wordpress.org/browser/everest-forms/tags/3.4.5/includes/class-evf-ajax.php#L1408
- https://plugins.trac.wordpress.org/browser/everest-forms/tags/3.4.5/includes/class-evf-ajax.php#L709
- https://plugins.trac.wordpress.org/browser/everest-forms/tags/3.5.1/includes/RestApi/controllers/version1/class-evf-modules.php#L315
- https://plugins.trac.wordpress.org/browser/everest-forms/tags/3.5.1/includes/RestApi/controllers/version1/class-evf-modules.php#L730
- https://plugins.trac.wordpress.org/browser/everest-forms/tags/3.5.1/includes/class-evf-ajax.php#L121
- https://plugins.trac.wordpress.org/browser/everest-forms/tags/3.5.1/includes/class-evf-ajax.php#L1408
- https://plugins.trac.wordpress.org/browser/everest-forms/tags/3.5.1/includes/class-evf-ajax.php#L709
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3634069%40everest-forms&new=3634069%40everest-forms
- https://www.wordfence.com/threat-intel/vulnerabilities/id/6d1ba996-e26c-45cc-ab95-338663f481d9?source=cve
Timeline
- nvd_ingest NVD