Sceawere

Vulnerability Detail

CVE-2026-13167UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Everest Forms Authorization Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
5h ago
Vendor
wpeverest
Product
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with delegated form management access and above, to activate arbitrary already-installed WordPress plugins — including previously deactivated or vulnerable plugins — without holding the core activate_plugins capability. Exploitation requires the target user to hold a delegated Everest Forms capability (manage_everest_forms, everest_forms_create_forms, or everest_forms_view_forms), which the plugin's own roles and permissions tool allows administrators to assign to non-administrator roles such as Author; the nonces required to exploit the AJAX handlers are emitted on EVF admin pages accessible to any such delegated user.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-16T05:16:46.077Z",
  "pubdate": "2026-08-16T05:16:46.077Z",
  "executiveSummary": "The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to an authorization bypass flaw impacting all versions up to, and including, 3.5.2.\nThe vulnerability stems from insufficient verification of user authorization to perform specific administrative actions within the plugin's AJAX handlers.\nAuthenticated attackers possessing delegated form management access can leverage this flaw to activate arbitrary already-installed WordPress plugins, including previously deactivated or vulnerable components, without holding the core activate_plugins capability.\nExploitation requires the target user to hold a delegated Everest Forms capability, such as manage_everest_forms, everest_forms_create_forms, or everest_forms_view_forms.\nThese capabilities can be assigned to non-administrator roles like Authors using the plugin's internal roles and permissions tool.\nRequired nonces for the AJAX handlers are exposed on Everest Forms administrative pages accessible to any such delegated user, lowering the barrier to successful exploitation.",
  "technicalDetails": "The root cause of the vulnerability is an authorization bypass resulting from missing permission checks within the plugin's AJAX request handlers.\nThe affected components are the administrative AJAX handlers associated with the Everest Forms plugin, which fail to validate whether the requesting user possesses the core WordPress activate_plugins capability before executing plugin activation routines.\nThe vulnerability affects all versions of the Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress up to, and including, 3.5.2.\nExploitation requires authentication and specific privilege requirements. Specifically, an attacker must compromise or utilize an account assigned a delegated Everest Forms capability, such as manage_everest_forms, everest_forms_create_forms, or everest_forms_view_forms.\nThese restricted capabilities can be assigned to lower-privileged roles like Author using the plugin's native roles and permissions configuration interface.\nThe attack flow proceeds as follows: First, the authenticated low-privileged user navigates to an Everest Forms administrative page where the necessary nonces for the AJAX handlers are dynamically emitted and exposed in the source or script context.\nSecond, the attacker formulates an AJAX request targeting the vulnerable plugin functionality, incorporating the harvested nonce to satisfy anti-CSRF checks.\nThird, because the backend logic fails to verify if the user holds the core activate_plugins capability, the application processes the request and executes the activation of arbitrary already-installed WordPress plugins.\nThis includes the ability to re-enable previously deactivated plugins or dormant vulnerable plugins that may expose additional attack vectors.\nThe network exposure is bounded by the WordPress administration interface access, requiring valid session credentials for a user with delegated form capabilities.\nPost-exploitation impact includes unauthorized state modification of the WordPress environment, specifically privilege escalation or capability abuse via the activation of vulnerable or malicious plugins already present on the file system."
}
CVE-2026-13167: Everest Forms Authorization Bypass Vulnerability (MEDIUM Severity, CVSS: 4.3) - Sceawere