Everest Forms Missing Authorization Vulnerability Allowing Unauthorized Email Sending

Vulnerability

A vulnerability exists in the Everest Forms WordPress plugin, specifically in versions through 3.4.7. The issue arises from a lack of proper capability checks in the send_test_email() function, allowing authenticated users with Subscriber-level access and above to send test emails to any email address from the server.

Impact

Exploitation of this vulnerability allows for unauthorized email sending, which could be misused for phishing or spam activities.

Remediation

Users can update to Everest Forms version 3.4.8 or later to address this vulnerability.

Added: May 28, 2026, 3:03 AM
Updated: May 28, 2026, 3:03 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
6.1
remediation
7.7
relevance
9.6
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.