Everest Forms
cpe:2.3:a:wpeverest:everest_forms:*:*:*:*:wordpress:*:*
- < 3.5.0
A vulnerability exists in the Everest Forms WordPress plugin in versions prior to 3.5.0, where temporary CSV files created during email notification processing are not consistently deleted. These files are left publicly accessible in the uploads directory, allowing unauthenticated attackers to access other users' form submission records through predictable, enumerable filenames. Exploitation requires the Everest Forms Pro add-on to be active, as the CSV email attachment feature is only available with Pro. The vulnerability arises when a form has multiple email notifications, with the CSV attachment enabled on a notification that is processed before the one where it is disabled. In such cases, the entry identifiers, which are sequential and returned to the submitter in the response, can be easily enumerated to retrieve the exposed CSV files.
This vulnerability leads to unauthorized access to sensitive form submission data from other users.
To reproduce this vulnerability, first ensure that both the Everest Forms (free) plugin and the Everest Forms Pro add-on are active. Create a form with the fields Name, Email, Subject, and Message. In the form's email settings, configure two notifications: one with the 'Send CSV attachment' option enabled and another with the option disabled, ensuring the latter is processed after the former. After publishing the form, submit it as a normal visitor. The response will include the entry ID, which can be used to access the CSV file generated by the first notification, as this file is not deleted after processing. This CSV file will contain the submitted form data, including potentially sensitive information.
Users are advised to update the Everest Forms WordPress plugin to version 3.5.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.