Everest Forms WordPress Plugin Unauthenticated Missing Authorization via Site Assistant REST Endpoints

Vulnerability

A vulnerability exists in the Everest Forms WordPress plugin in versions prior to 3.5.0, where several REST API endpoints related to the onboarding assistant do not properly restrict access. The capability check can be bypassed by omitting or altering a specific request header, allowing unauthenticated attackers to read onboarding status, modify plugin options, and send test emails to arbitrary addresses.

Impact

Exploitation of this vulnerability allows for unauthorized access to onboarding status information, manipulation of plugin options, and the ability to send emails from the site to any chosen recipient.

Reproduction

The vulnerability can be reproduced by sending requests to the affected REST API endpoints without authentication. The 'Referer' header can be omitted or changed to bypass the capability check. Once the request is accepted, the onboarding status can be read, options can be modified, and test emails can be sent to arbitrary addresses.

Remediation

Users are advised to update the Everest Forms WordPress plugin to version 3.5.0 or later.

Added: Jul 9, 2026, 7:28 AM
Updated: Jul 9, 2026, 7:28 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
1.3
exploitability
9.7
remediation
7.7
relevance
9.2
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.