Vulnerability Description
The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users' form submission records via predictable, enumerable filenames.
CVSS Score
HIGH
References
FAQ
What is CVE-2026-11571?
CVE-2026-11571 is a vulnerability with a CVSS score of 7.5 (HIGH). The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads director...
How severe is CVE-2026-11571?
CVE-2026-11571 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-11571?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.