216.73.217.22

CVE-2026-4888

· Published 28/05/2026 00:16 · Modified 28/05/2026 13:45

Labels: CVE-2026-4888 2026-05-28CVE-2026-4888CWE-862[email protected]

Essential information

Published
28/05/2026 00:16
Modified
28/05/2026 13:45
Author
Creator
CVSS
4.3 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CVSS metrics

Description

The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 3.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to send test emails to arbitrary addresses from the server.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wordpress / everest forms cpe:2.3:a:wordpress:everest_forms:<3.4.7:*:*:*:*:wordpress:*:*

References