Vulnerability Intelligence Report
Everest Forms < 3.5.0 - Unauthenticated Sensitive Information Exposure via Residual CSV Artifacts
CVE-2026-11571
The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users' form submission records via predictable, enumerable filenames.
No Active Exploit Signals
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:0.26%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-200 ↗CWE-200 Information Exposure
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Unknown | Everest Forms | 0 < 3.5.0 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.256%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | WPScan · Vendor · France |
| Reserved | 2026-06-08T09:36:35 |
| Published | 2026-07-09T06:00:02 |
| Last Updated | 2026-07-09T14:39:49 |
Community Chatter & Buzz