Server-Side Request Forgery Vulnerability in Everest Forms Plugin for WordPress
CVE-2026-5096
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 August 2026
What is CVE-2026-5096?
The Everest Forms plugin for WordPress is susceptible to Server-Side Request Forgery (SSRF), impacting all versions up to and including 3.4.4. This vulnerability arises from the load_previous_field_value() method in class-evf-form-task.php, which inadequately validates URLs submitted via $_POST data for upload fields. Consequently, this allows attackers to provide arbitrary URLs, leading to unprotected HTTP HEAD requests sent from the WordPress server to malicious endpoints. This manipulation can be executed by unauthenticated users through a form submission that triggers a re-rendering of the form by leaving a required field blank.
Affected Version(s)
Everest Forms β Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI 0 <= 3.4.4