Everest Forms
cpe:2.3:a:wpeverest:everest_forms:*:*:*:*:wordpress:*:*
- <= 3.4.7
A vulnerability exists in the Everest Forms WordPress plugin, specifically in versions through 3.4.7. The issue arises from a lack of proper capability checks in the send_test_email() function, allowing authenticated users with Subscriber-level access and above to send test emails to any email address from the server.
Exploitation of this vulnerability allows for unauthorized email sending, which could be misused for phishing or spam activities.
Users can update to Everest Forms version 3.4.8 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.