Summary
CVE-2026-11571 is a high-severity sensitive information exposure vulnerability affecting the Everest Forms WordPress plugin in all versions prior to 3.5.0. The flaw stems from the plugin’s failure to reliably delete temporary CSV files generated during email-notification processing, leaving those files publicly accessible in the WordPress uploads directory under predictable, enumerable paths. Any unauthenticated remote attacker can enumerate and download other users’ form submission records containing personal and potentially sensitive data.
Technical details
- Root cause: When email notifications with CSV attachments are triggered, the plugin writes temporary CSV exports of form entries to a fixed uploads subdirectory (
/wp-content/uploads/Everes-Froms-Entries-CSV-file/) and fails to reliably delete them after the notification is sent, leaving the files world-readable via direct HTTP request. - Trigger conditions: Exploitation requires that the target site uses the Everest Forms Pro add-on and has configured multiple email notifications with CSV export enabled on at least one non-final notification step.
- Enumeration method: Exported CSV filenames follow the pattern
Entry data-[ID].csv; entry IDs are sequential and are disclosed in form submission responses, making enumeration trivial — an HTTP 200 response confirms a valid file while HTTP 404 confirms absence. - Attack vector: Fully network-exploitable with no authentication, no credentials, and no victim interaction required. An attacker sends a plain HTTP GET request to the predictable file path.
- Impact: Confidentiality breach. Retrieved CSV files contain all fields submitted by other users, which typically include names, email addresses, phone numbers, and any other data collected by the form owner. There is no impact on integrity or availability.
- CWE: CWE-200 – Exposure of Sensitive Information to an Unauthorized Actor.
Affected software
- Everest Forms (free WordPress plugin, slug:
everest-forms), all versions < 3.5.0 - Exploitation additionally requires the Everest Forms Pro add-on with CSV email-notification attachments configured.
Severity
- CVSS v3.1 Base Score: 7.5 (HIGH)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate — update the plugin: Upgrade Everest Forms to version 3.5.0 or later (current release: 3.5.2, published July 2, 2026). Version 3.5.0 (released June 15, 2026) contains the security fix for this issue.
- If immediate patching is not possible:
- Disable email notifications that use CSV attachments until the plugin is updated.
- Restrict direct HTTP access to the
/wp-content/uploads/Everes-Froms-Entries-CSV-file/directory at the web server level (e.g., via.htaccessdeny rules or equivalent Nginx configuration) to prevent unauthenticated file retrieval. - Audit the uploads directory for any residual CSV files and remove them manually.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

