Everest Forms
cpe:2.3:a:wpeverest:everest_forms:*:*:*:*:wordpress:*:*
- <= 1.9.4
A vulnerability allowing arbitrary file deletion has been identified in the Everest Forms (Pro) plugin for WordPress, affecting all versions through 1.9.4. The issue arises from inadequate file path validation in the delete_entry_files() function, enabling unauthenticated attackers to delete arbitrary files on the server. This deletion can lead to remote code execution if critical files, such as wp-config.php, are removed. The vulnerability requires an admin to initiate the deletion by removing a form entry, preventing the attacker from exploiting it independently.
Exploitation of this vulnerability allows for unauthorized deletion of files on the server, which could be leveraged for remote code execution, particularly if a sensitive file is deleted.
Users are advised to update to Everest Forms Pro version 1.9.5 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.