CVE-2026-5478Disclosure

LOWCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3.4.4. This is due to the plugin trusting attacker-controlled old_files data from public form submissions as legitimate server-side upload state, and converting attacker-supplied URLs into local filesystem paths using regex-based string replacement without canonicalization or directory boundary enforcement. This makes it possible for unauthenticated attackers to read arbitrary local files (e.g., wp-config.php) by injecting path-traversal payloads into the old_files upload field parameter, which are then attached to notification emails. The same path resolution is also used in the post-email cleanup routine, which calls unlink() on the resolved path, resulting in the targeted file being deleted after being attached. This can lead to full site compromise through disclosure of database credentials and authentication salts from wp-config.php, and denial of service through deletion of critical files. Prerequisite: The form must contain a file-upload or image-upload field, and disable storing entry information.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-20); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-20: 2Mentions · 2026-04-21: 1PoC Mentioned / Linked · 2026-04-20: 1Technical Details · 2026-04-20: 2Technical Details · 2026-04-21: 104-2004-21
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-202
Disclosure2
2026-04-211
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-5478 The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and including, 3.4.4. This is due to the plugin trusting… https://www.cve.org/CVERecord?id=CVE-2026-5478

    Post summary

    This text announces CVE-2026-5478, noting that the Everest Forms WordPress plugin up to version 3.4.4 allows arbitrary file read and deletion, without reference to patches, PoC, or active exploitation.

    00000101
    57.2K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-5478 The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and inc… CVSS 8.1 Full analysis → https://sec.kaitan.id/cves/CVE-2026-5478 #WordPress #CyberSecurity #InfoSec

    Post summary

    A newly disclosed high‑severity vulnerability (CVE‑2026‑5478) in the Everest Forms WordPress plugin allows arbitrary file read and deletion, with a CVSS score of 8.1.

    000005
    124 followersView on X
  • Abu Hurayra 🇵🇸❤️🇧🇩@HurayraIIT
    Disclosure

    CVE-2026-5478: Path Traversal File Read in Everest Forms @everestforms https://hurayraiit.com/blog/cve-2026-5478-path-traversal-file-read-in-everest-forms/

    Post summary

    The post announces CVE-2026-5478, a path traversal flaw in Everest Forms, linking to a blog discussing the vulnerability details.

    0000034
    85 followersView on X

Explore more