Unrated severityNVD Advisory· Published Jul 9, 2026· Updated Jul 9, 2026
Everest Forms < 3.5.0 - Unauthenticated Sensitive Information Exposure via Residual CSV Artifacts
CVE-2026-11571
Description
The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users' form submission records via predictable, enumerable filenames.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/4bd381e9-2f4e-4e61-99af-88f50aed71f5/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.