CVE-2026-11571
The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing
CVSS
7.5
High
EPSS
0.3%
p17
KEV
—
Exploit Today
5
0-100
Published: Jul 9, 2026 · Last modified: Jul 9, 2026
0.1%EPSS · 30 days0.3%
2026-07-092026-07-20
The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leaves them publicly accessible in the uploads directory, allowing unauthenticated attackers to retrieve other users' form submission records via predictable, enumerable filenames.
No related CVEs by CWE or product.