WordPress Plugin Vulnerability Exposes 100,000 Sites to Complete Site Takeover Attacks
Brief
A critical vulnerability tracked as CVE-2026-19598 in the Everest Forms WordPress plugin has exposed more than 100,000 websites to complete site takeover attacks.
The flaw has a CVSS severity score of 9.
- It can allow unauthenticated attackers to upload malicious files, execute code remotely, and potentially gain full control of affected WordPress sites.
The vulnerability detailed by Wordfence affects Everest Forms versions before 3.
- 9.
- It exists in the plugin’s file-upload handling logic, specifically in the EVF_Form_Fields_Upload class.
Insufficient validation of file types and paths can enable attackers to upload arbitrary files, including PHP scripts that the web server may execute.
WordPress Plugin Vulnerability Exposed
An attacker does not need a valid WordPress account to exploit the issue.
