Mastodon Skip to content
pulseofnations. Real News. Global Impact.
Subscribe
live markets
S&P 5007,677.28▲ 3.58%NASDAQ26,151.30▲ 4.71%DOW53,577.40▲ 3.14%GOLD4,699.60▲ 15.34%WTI80.33▼ 2.76%BRENT85.25▼ 3.52%EUR/USD1.1667▲ 2.55%USD/JPY159.01▼ 2.94%DXY98.98▼ 2.50%BTC$79,015▼ 1.73%ETH$2,466▼ 1.27%SOL$96.94▼ 4.34%TOTAL CRYPTO$2.68T▼ 4.10%

Critical Everest Forms Flaw Exposes 100K WordPress Sites

CVSS 9.8 vulnerability in Everest Forms plugin allows unauthenticated attackers to upload PHP web shells and take over WordPress sites

Partner Surfshark VPN

A critical vulnerability in the Everest Forms WordPress plugin has exposed more than 100,000 websites to complete site takeover, with researchers warning that unauthenticated attackers can upload malicious PHP web shells and gain full control.

The flaw, tracked as CVE-2026-19598 and carrying a CVSS severity score of 9.8, was disclosed by Wordfence on August 24. It affects Everest Forms versions before 3.0.9.5 and exists in the plugin’s file-upload handling logic within the EVF_Form_Fields_Upload class. Insufficient validation of file types and paths allows attackers to upload arbitrary files, including executable PHP scripts.

Attack Requires No Authentication

What makes the vulnerability particularly dangerous is that it requires no WordPress account to exploit. By targeting a vulnerable form-upload feature with specially crafted HTTP requests, an attacker can place a PHP web shell on the server. This gives them a remote interface to run commands, browse files, steal databases, modify site content, or install additional malware.

The potential damage extends well beyond website defacement. Attackers with remote code execution access can extract the WordPress configuration file containing database credentials, create unauthorized administrator accounts, modify themes and plugins, and inject malicious JavaScript into pages visited by users. This can turn compromised sites into platforms for phishing, malware distribution, SEO spam, or credential theft.

Urgent Patching Required

Website administrators should update Everest Forms to version 3.0.9.5 or later immediately. Sites that cannot be patched quickly should temporarily disable the plugin, particularly if it runs public-facing file-upload forms. Organizations should also check for signs of compromise by reviewing administrator accounts for unauthorized users, inspecting upload directories for recently created PHP files, and examining server logs for suspicious requests targeting Everest Forms endpoints.

The vulnerability is the latest in a series of critical flaws targeting WordPress plugins this year. WordPress 7.0.4, released in early August, patched an authenticated remote code execution issue, while other plugin vulnerabilities have continued to surface across the ecosystem. The Everest Forms flaw is notable for its combination of high severity, low attack complexity, and the massive installed base of more than 100,000 active sites.

Security teams that suspect compromise should rotate all WordPress, database, hosting-panel, FTP, SSH, and API credentials. Affected files should be restored from known-good backups, unauthorized administrator accounts removed, and a full review of plugins, themes, scheduled tasks, and server-side persistence mechanisms conducted.

SourcesCyber Security News; Wordfence Security Advisory (August 24, 2026); National Vulnerability Database
React to this dispatch
Share this dispatch X WhatsApp Bluesky Report an error
Written by

Founder and editor of Pulse of Nations, an independent wire service covering war, geopolitics, markets and technology.

discussion

Leave a Reply

Next dispatch North Korea Deploys AI-Built Chrome Extension to Steal Gmail Read →