CVE-2026-13167
Received Received - Intake

Authorization Bypass in Everest Forms WordPress Plugin

Vulnerability report for CVE-2026-13167, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-16

Last updated on: 2026-08-16

Assigner: Wordfence

Description

The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with delegated form management access and above, to activate arbitrary already-installed WordPress plugins β€” including previously deactivated or vulnerable plugins β€” without holding the core activate_plugins capability. Exploitation requires the target user to hold a delegated Everest Forms capability (manage_everest_forms, everest_forms_create_forms, or everest_forms_view_forms), which the plugin's own roles and permissions tool allows administrators to assign to non-administrator roles such as Author; the nonces required to exploit the AJAX handlers are emitted on EVF admin pages accessible to any such delegated user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-16
Last Modified
2026-08-16
Generated
2026-08-16
AI Q&A
2026-08-16
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
everest_forms everest_forms to 3.5.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in the Everest Forms WordPress plugin up to version 3.5.2. It allows authenticated attackers with delegated form management access to activate arbitrary WordPress plugins without proper capability verification. The issue arises because the plugin does not check if users have the core activate_plugins capability before allowing plugin activation.

Detection Guidance

To detect this vulnerability, check WordPress sites running Everest Forms versions up to 3.5.2. Review user roles with delegated Everest Forms capabilities (manage_forms, create_forms, view_forms) for non-administrators. Inspect server logs for unauthorized plugin activation attempts via AJAX handlers on EVF admin pages.

Impact Analysis

If exploited, this vulnerability could allow attackers to reactivate previously disabled or vulnerable plugins on your WordPress site. This could lead to further security issues, such as enabling malicious plugins that compromise site integrity, steal data, or perform unauthorized actions.

Compliance Impact

This vulnerability could indirectly impact compliance by allowing unauthorized plugin activation, which may introduce data breaches or unauthorized access to sensitive information. For GDPR, this could lead to unauthorized processing of personal data. For HIPAA, it might expose protected health information if vulnerable plugins are reactivated.

Mitigation Strategies

Update the Everest Forms plugin to the latest version beyond 3.5.2 to patch the authorization bypass vulnerability. Remove any delegated form management capabilities from non-administrator roles if not required. Regularly audit user roles and permissions to ensure least privilege access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13167. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart