Everest Forms (Pro) Arbitrary File Deletion Vulnerability

Vulnerability

A vulnerability allowing arbitrary file deletion has been identified in the Everest Forms (Pro) plugin for WordPress, affecting all versions through 1.9.4. The issue arises from inadequate file path validation in the delete_entry_files() function, enabling unauthenticated attackers to delete arbitrary files on the server. This deletion can lead to remote code execution if critical files, such as wp-config.php, are removed. The vulnerability requires an admin to initiate the deletion by removing a form entry, preventing the attacker from exploiting it independently.

Impact

Exploitation of this vulnerability allows for unauthorized deletion of files on the server, which could be leveraged for remote code execution, particularly if a sensitive file is deleted.

Remediation

Users are advised to update to Everest Forms Pro version 1.9.5 or a newer patched version.

Added: Jun 25, 2025, 10:30 AM
Updated: Jun 25, 2025, 10:30 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
10.0
exploitability
6.5
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.