Critical Everest Forms WordPress Plugin Vulnerability Exposes 100,000+ Sites to Takeover
A severe vulnerability (CVE-2026-19598) in the Everest Forms WordPress plugin has left over 100,000 websites vulnerable to complete site takeover via unauthenticated remote code execution (RCE). The flaw, rated 9.8 on the CVSS scale, stems from inadequate file-type and path validation in the plugin’s EVF_Form_Fields_Upload class, affecting versions prior to 3.0.9.5.
Attackers can exploit the vulnerability by submitting maliciously crafted requests to the plugin’s file-upload feature, allowing them to upload arbitrary files including PHP web shells without requiring valid WordPress credentials. Once deployed, a web shell grants attackers full remote control, enabling them to execute commands, steal databases, modify site content, or inject malicious JavaScript into visitor-facing pages.
The impact extends beyond defacement: threat actors can extract database credentials, create unauthorized administrator accounts, alter themes/plugins, or delete critical files like wp-config.php, potentially forcing a WordPress site into installation mode and hijacking its database. Compromised sites may also be repurposed for phishing, malware distribution, SEO spam, or credential theft.
Security firm Wordfence reported the issue and confirmed its firewall blocks exploitation attempts. Administrators are urged to update to Everest Forms 3.0.9.5 or later immediately. Those unable to patch should disable the plugin, particularly if public file-upload forms are in use. Indicators of compromise include unauthorized admin accounts, suspicious PHP files in upload directories, or unusual log activity targeting Everest Forms endpoints. Suspected breaches warrant credential rotation, backup restoration, and a full review of plugins, themes, and server-side persistence mechanisms.
Source: https://cybersecuritynews.com/wordpress-everest-forms-plugin-flaw/
Everest Forms TPRM report: https://www.rankiteo.com/company/everest-software
"id": "eve1787578403",
"linkid": "everest-software",
"type": "Vulnerability",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Various (WordPress-based sites)',
'location': 'Global',
'name': 'Everest Forms WordPress Plugin Users',
'size': '100,000+ sites',
'type': 'Websites'}],
'attack_vector': 'Unauthenticated file upload via plugin vulnerability',
'data_breach': {'data_exfiltration': 'Potential (via web shell)',
'file_types_exposed': ['PHP web shells',
'Malicious JavaScript'],
'personally_identifiable_information': 'Potential',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Database credentials',
'Personally identifiable '
'information (potential)',
'Payment information '
'(potential)']},
'description': 'A severe vulnerability (CVE-2026-19598) in the Everest Forms '
'WordPress plugin has left over 100,000 websites vulnerable to '
'complete site takeover via unauthenticated remote code '
'execution (RCE). The flaw stems from inadequate file-type and '
'path validation in the plugin’s `EVF_Form_Fields_Upload` '
'class, allowing attackers to upload arbitrary files including '
'PHP web shells without requiring valid WordPress credentials. '
'Once deployed, a web shell grants attackers full remote '
'control, enabling them to execute commands, steal databases, '
'modify site content, or inject malicious JavaScript into '
'visitor-facing pages.',
'impact': {'brand_reputation_impact': 'High (potential for phishing, malware '
'distribution, SEO spam, or credential '
'theft via compromised sites)',
'data_compromised': 'Database credentials, personally identifiable '
'information, payment information (potential)',
'identity_theft_risk': 'High (if personally identifiable '
'information is exfiltrated)',
'operational_impact': 'Complete site takeover, unauthorized '
'administrative access, potential deletion '
'of critical files (e.g., `wp-config.php`)',
'payment_information_risk': 'High (if payment data is stored or '
'processed on compromised sites)',
'systems_affected': 'WordPress sites using Everest Forms plugin '
'(versions prior to 3.0.9.5)'},
'post_incident_analysis': {'corrective_actions': 'Patch vulnerability '
'(version 3.0.9.5), improve '
'file-upload validation, '
'monitor for exploitation '
'attempts',
'root_causes': 'Inadequate file-type and path '
'validation in the '
'`EVF_Form_Fields_Upload` class'},
'recommendations': ['Update to Everest Forms 3.0.9.5 or later immediately',
'Disable the plugin if unable to patch, especially if '
'public file-upload forms are in use',
'Check for unauthorized admin accounts, suspicious PHP '
'files in upload directories, or unusual log activity',
'Rotate credentials and restore from backups if '
'compromised',
'Review plugins, themes, and server-side persistence '
'mechanisms'],
'references': [{'source': 'Wordfence'}],
'response': {'containment_measures': 'Update to Everest Forms 3.0.9.5 or '
'later, disable the plugin if unable to '
'patch',
'enhanced_monitoring': 'Review logs for unusual activity '
'targeting Everest Forms endpoints',
'remediation_measures': 'Rotate credentials, restore from '
'backups, review plugins/themes, check '
'for server-side persistence mechanisms',
'third_party_assistance': 'Wordfence (reported the issue and '
'confirmed firewall blocks '
'exploitation attempts)'},
'title': 'Critical Everest Forms WordPress Plugin Vulnerability Exposes '
'100,000+ Sites to Takeover',
'type': 'Remote Code Execution (RCE)',
'vulnerability_exploited': 'CVE-2026-19598 (Inadequate file-type and path '
'validation in `EVF_Form_Fields_Upload` class)'}