9.8
CVSSv3

CVE-2025-1128

CVSSv4: NA | CVSSv3: 9.8 | CVSSv2: NA | VMScore: 1000 | EPSS: 0.00766 | KEV: Not Included
Published: 25/02/2025 Updated: 25/02/2025

Vulnerability Summary

Unauthenticated Arbitrary File Upload, Read, and Delete in Everest Forms WordPress Plugin

The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due to missing file type and path validation in the 'format' method of the EVF_Form_Fields_Upload class in all versions up to, and including, 3.0.9.4. This makes it possible for unauthenticated malicious users to upload, read, and delete arbitrary files on the affected site's server which may make remote code execution, sensitive information disclosure, or a site takeover possible.

Vulnerability Trend