← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 24, 2026 · 13:08via Cyber Security News

WordPress Plugin Vulnerability Exposes 100,000 Sites to Complete Site Takeover Attacks

Brief

A critical vulnerability tracked as CVE-2026-19598 in the Everest Forms WordPress plugin has exposed more than 100,000 websites to complete site takeover attacks.

The flaw has a CVSS severity score of 9.

  • It can allow unauthenticated attackers to upload malicious files, execute code remotely, and potentially gain full control of affected WordPress sites.

The vulnerability detailed by Wordfence affects Everest Forms versions before 3.

  • 9.
  • It exists in the plugin’s file-upload handling logic, specifically in the EVF_Form_Fields_Upload class.

Insufficient validation of file types and paths can enable attackers to upload arbitrary files, including PHP scripts that the web server may execute.

WordPress Plugin Vulnerability Exposed

An attacker does not need a valid WordPress account to exploit the issue.

Read more on Cyber Security News