Everest Forms: Unauthenticated File Upload Flaw (CVE-2026-19598)

Introduction

Everest Forms, installed on more than 100,000 WordPress sites, had a critical vulnerability disclosed as CVE-2026-19598 (CVSS 9.8) that lets an unauthenticated visitor upload an unexpected file type and run it on your server — a direct path to full control of the site. Versions before 3.0.9.5 are affected.

Like several other recent WordPress form-plugin vulnerabilities, the root cause is insufficient validation on file upload fields, which are a standard, often public-facing feature of form plugins — making the vulnerable code path reachable by anyone who finds a form on your site.

What You Should Do Right Now

  1. Check if Everest Forms is installed under Plugins in wp-admin, and confirm the version.
  2. Back up your site immediately before updating.
  3. Update to 3.0.9.5 or later right away.
  4. Check your uploads directory (especially any folders tied to form submissions) for unfamiliar PHP files.
  5. Review your admin user list for anything unfamiliar, in case the site was already touched before you could patch.

Why Form Plugins Keep Showing Up in These Alerts

File-upload form fields are one of the few places on a typical WordPress site where an anonymous visitor’s input directly becomes a file on your server. That makes form plugins a recurring target — we’ve now covered similar file-upload issues in Forminator and Elementor Pro’s Forms module this month alone. If your site uses any plugin with a public file-upload form field, treat it as a standing priority to keep updated, not a “set it and forget it” feature.

FAQ

Do I need a file upload field enabled to be at risk?
Check the vendor’s advisory for exact preconditions, but as a general rule, update regardless of whether you’re actively using file uploads — the vulnerable code path may still be reachable.

How do I check for a planted file?
Look through your uploads directory via FTP/SFTP or your host’s file manager for any PHP file where only images or documents should be.

Is the free or pro version affected?
Check your installed version against 3.0.9.5 regardless of edition.

Conclusion

Another 9.8-severity, unauthenticated file-upload flaw on a widely-installed form plugin. Update to 3.0.9.5+, back up first, and check for signs of prior tampering.

Back up before every emergency update

Nota Backup & Restore keeps automatic, off-site backups and lets you recover even when wp-admin is down. Start your 14-day free trial — no credit card required.