CVE-2025-5927

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

The Everest Forms (Pro) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_entry_files() function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The vulnerability requires an admin to trigger the deletion via deletion of a form entry and cannot be carried out by the attacker alone.

<p><strong>The Best Free WordPress Contact Form Builder</strong></p> <p>Build any form you need with a single plugin. Everest Forms combines a drag-and-drop form builder, payment processor, quiz maker, and survey tool with 40+ form fields and unlimited submissions.</p> <p>Over 100,000+ WordPress websites trust it for everything from simple contact forms to complex applications.</p> <p>Everest Forms includes pro-level features like Form Entries, File Uploads, Admin Approval, and Survey Fields in the free version, so you can build professional forms from day one.</p> <p>👉 <a href="https://demo.tastewp.com/everest-forms" rel="nofollow ugc">Try Everest Forms</a> (Clicking this link creates a demo where you can test Everest Forms.)</p> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/AvK0KU2ycqc?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <p>From contact forms to complex applications with Conditional Logic, Payment Processing, and Webhooks, Everest Forms grows alongside your business needs.</p> <p><a href="https://everestforms.net/features/?utm_source=wporg&amp;utm_medium=all-feature-link&amp;utm_campaign=evf-readme" rel="nofollow ugc">Explore All Features</a> | <a href="https://everestforms.net/pricing/?utm_source=wporg&amp;utm_medium=docs-top-link&amp;utm_campaign=evf-readme" rel="nofollow ugc">Upgrade to Everest Forms Pro</a></p> <h3>Get the Best Form Building Experience with Everest Forms</h3> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/35CznJES5Uo?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <h3>Create any type of forms with Everest Forms:</h3> <ul> <li><strong>Contact &amp; Communication Forms</strong> Contact forms, support request forms, feedback forms, callback request forms, inquiry forms, customer service forms.</li> <li><strong>Lead Generation Forms</strong> Newsletter signup forms, quote request forms, demo request forms, consultation booking forms, product inquiry forms.</li> <li><strong>E-Commerce &amp; Payment Forms</strong> Order forms, donation forms, payment forms, booking forms, registration forms, subscription forms.</li> <li><strong>Survey &amp; Research Forms</strong> Customer satisfaction surveys, market research surveys, event feedback forms, poll forms, voting forms.</li> <li><strong>Application &amp; Submission Forms</strong> Job application forms, volunteer application forms, membership application forms, proposal submission forms.</li> <li><strong>Interactive &amp; Engagement Forms</strong> Quiz forms, poll forms, calculator forms, conversational forms, multi-step forms, personality test forms.</li> </ul> <p><a href="https://everestforms.net/form-templates/?utm_source=wporg&amp;utm_medium=all-feature-link&amp;utm_campaign=evf-readme" rel="nofollow ugc">View Form Templates</a></p> <h3>Why Everest Forms is the Best Choice for WordPress Forms</h3> <p>Building WordPress forms should be simple, powerful, and affordable; Everest Forms delivers on all three.</p> <h3>More Features in Free Version</h3> <p>While other plugins charge premium prices for file uploads and advanced fields, Everest Forms includes file uploads, image uploads, and 35+ essential form fields absolutely free. No artificial limitations.</p> <h3>Built for Real Businesses</h3> <p>Create payment forms with Stripe and PayPal, generate PDF submissions for invoices and contracts, and collect entries with unlimited storage—all without upgrading.</p> <h3>Designed for Speed and Simplicity</h3> <p>Our intuitive drag-and-drop builder lets you create professional forms in under 5 minutes. Choose from 40+ pre-built templates or start from scratch.</p> <h3>Enterprise Features at Startup Prices</h3> <p>Get advanced capabilities like multi-step forms, conversational forms, AI-powered contact forms, and landing pages—features that cost thousands on other platforms.</p> <h3>Drag and Drop Form Builder</h3> <ul> <li><strong>Intuitive Form Builder</strong> Create forms in minutes with drag-and-drop simplicity. Add fields, rearrange layouts, and customize settings without touching code.</li> <li><strong>Style Customizer</strong> Match forms to your brand with our visual style editor. Customize colors, fonts, spacing, borders, and backgrounds in real time.</li> <li><strong>Popup Forms</strong> Display forms in elegant popups to capture attention without interrupting the user experience.</li> <li><strong>Mobile Responsive</strong> Forms automatically adapt to any screen size, ensuring perfect display on desktop, tablet, and mobile devices.</li> <li><strong>Multiple Embed Options</strong> Add forms using Gutenberg blocks, shortcodes, or the quick &#8220;Embed&#8221; button. Works with any page builder.</li> </ul> <h3>Entry Management</h3> <ul> <li><strong>Unlimited Entry Storage</strong> Store every form submission securely in your WordPress database with no limits on volume.</li> <li><strong>Powerful Entry Dashboard</strong> View, search, sort, and filter all submissions from an organized admin interface.</li> <li><strong>Entry Management Tools</strong> Edit entries, delete spam submissions, restore deleted entries, and bulk manage data effortlessly.</li> <li><strong>Export Submissions</strong> Download entries as CSV files for analysis in Excel, Google Sheets, or other data tools.</li> </ul> <h3>Antispam and Security</h3> <ul> <li><strong>Multi-Layer Spam Defense</strong> Protect forms with Google reCAPTCHA, hCAPTCHA, Cloudflare Turnstile, custom CAPTCHA, Honeypot, and Akismet integration.</li> <li><strong>CleanTalk Anti-Spam</strong> Stop spam in real time with cloud-based filtering that blocks bots without frustrating real users.</li> <li><strong>GDPR Compliance Tools</strong> Add privacy policy checkboxes, consent fields, and data handling disclosures to meet privacy regulations.</li> </ul> <h3>Everest Forms Complete Feature List (Free and Pro)</h3> <h3>Intuitive From Builder</h3> <ul> <li>Unlimited Forms</li> <li>Powerful Form Builder</li> <li>35+ Form Fields</li> <li>Style Customizer</li> <li>Entry Management</li> <li>File Uploads</li> <li>Image Uploads</li> <li>After Submission Behavior</li> <li>User Redirection</li> <li>Form Import and Export</li> <li>Popup Forms</li> <li>Form Templates</li> </ul> <h3>Entry Management</h3> <ul> <li>Unlimited Entries</li> <li>Admin Approval for Entries</li> <li>PDF from Submission</li> <li>Cloud Storage</li> <li>Search Entries</li> <li>Entry Report</li> <li>Sort Entries</li> <li>Export Entries</li> <li>Manage and Delete Entries</li> <li>CSV Export</li> <li>Notifications</li> </ul> <h3>Antispam and Security</h3> <ul> <li>Custom CAPTCHA</li> <li>Google reCAPTCHA</li> <li>hCaptcha</li> <li>Honeypot</li> <li>Akismet</li> <li>CleanTalk</li> <li>Domain Whitelist/Blacklist</li> <li>Cloudflare Turnstile</li> <li>IP Blocking</li> <li>GDPR Compliance</li> </ul> <h3>Page Builder Compatibility</h3> <ul> <li>Elementor</li> <li>Divi</li> <li>Bricks Builder</li> <li>Oxygen Builder</li> <li>Beaver Builder</li> <li>WPBakery Builder</li> </ul> <h3>Payment &amp; Ecommerce</h3> <ul> <li>Payment &amp; eCommerce</li> <li>Stripe</li> <li>PayPal Standard</li> <li>Mollie Payment</li> <li>Square Payment</li> <li>Razorpay</li> <li>Authorize.Net</li> <li>Coupons</li> <li>Recurring</li> </ul> <h3>Advanced Form Features</h3> <ul> <li>Survey, Polls, and Quiz</li> <li>Multi Step Forms</li> <li>Conversational Forms</li> <li>Frontend Listing</li> <li>Save and Continue</li> <li>Repeater Fields</li> <li>User Registration</li> <li>Calculations</li> <li>Post Submissions</li> <li>Form Landing Page</li> <li>QR Generator</li> <li>E-signature</li> <li>Conditional Logic</li> <li>Webhook</li> <li>Advanced Form Analytics</li> <li>Geolocation</li> <li>Form Restriction</li> <li>Smart Tags Support</li> <li>AJAX Submission</li> </ul> <h3>Notification and Communication</h3> <ul> <li>Email Notifications</li> <li>Multiple Email Recipients</li> <li>Email Templates</li> <li>Twilio</li> <li>ClickSend</li> <li>Telegram</li> <li>Slack</li> </ul> <h3>CRM Integration</h3> <ul> <li>HubSpot</li> <li>OnePageCRM</li> <li>Pipedrive</li> <li>Zoho CRM</li> <li>Salesforce</li> <li>Salesflare</li> <li>amoCRM</li> </ul> <h3>Email Marketing Integrations</h3> <ul> <li>MailPoet</li> <li>Moosend</li> <li>Mailchimp</li> <li>MailerLite</li> <li>ActiveCampaign</li> <li>ConvertKit</li> <li>Campaign Monitor</li> <li>Drip</li> <li>GetResponse</li> <li>Brevo</li> <li>iContact</li> <li>Constant Contact</li> <li>AWeber</li> <li>CleverReach</li> <li>GetGist</li> </ul> <h3>Advanced Integrations</h3> <ul> <li>Zapier</li> <li>Google Sheets</li> <li>Google Calendar</li> <li>Google Drive</li> <li>Dropbox</li> <li>Trello</li> </ul> <h3>What Do People Say About Everest Forms?</h3> <p>⭐⭐⭐⭐⭐</p> <h4>The Best Contact Form for WordPress</h4> <p>“I tried so many contact forms for WordPress, but all of them lack one (or more) important features. Finally, I came across Everest Forms, and it solved all my problems.”</p> <p>-Baxtrip</p> <p>⭐⭐⭐⭐⭐</p> <h4>Easy to Use Contact Form</h4> <p>“Easy to use, looks good on the website, and the support was great when I needed help.”</p> <p>-Winwickmum</p> <p>⭐⭐⭐⭐⭐</p> <h4>Exceptional Plugin for Effortless Website Visitor Information Management</h4> <p>“The user-friendly interface ensures that visitors can submit their information with ease, contributing to a positive user experience. The PDF attachment delivered to my email is well-organized, making it a breeze to review and manage the collected data.”</p> <p>-Somaweera</p> <p>⭐⭐⭐⭐⭐</p> <h4>Must-Have Tool for Any Website Owner</h4> <p>“I’m extremely satisfied with this form builder plugin, and I highly recommend it to anyone looking for an easy and efficient way to create beautiful and functional forms for their WordPress site.”</p> <p>-Dev Kabir</p> <h3>Getting Started:</h3> <ul> <li><a href="https://www.youtube.com/@EverestForms" rel="nofollow ugc">Watch our video tutorials</a></li> <li><a href="https://docs.everestforms.net/docs/how-to-create-a-form-with-everest-forms/" rel="nofollow ugc">Follow our getting started documentation</a></li> </ul> <h3>Step-by-Step Everest Forms Tutorials for a Headstart</h3> <ul> <li><a href="https://everestforms.net/blog/create-wordpress-contact-form/" rel="nofollow ugc">How to Create Contact Form in WordPress?</a></li> <li><a href="https://everestforms.net/blog/how-to-make-a-quiz-in-wordpress/" rel="nofollow ugc">How to Make a Quiz in WordPress?</a></li> <li><a href="https://docs.everestforms.net/docs/how-to-stop-spam-on-wordpress-contact-form/" rel="nofollow ugc">How to Stop Spam on WordPress Contact Form?</a></li> <li><a href="https://everestforms.net/blog/wordpress-online-booking-form/" rel="nofollow ugc">How to Create a WordPress Online Booking Form for Hotels?</a></li> <li><a href="https://everestforms.net/blog/how-to-create-a-donation-form-in-wordpress/" rel="nofollow ugc">How to Create a Donation Form in WordPress?</a></li> <li><a href="https://everestforms.net/blog/create-multi-step-form-in-wordpress/" rel="nofollow ugc">How to Create a WordPress Multi-step Form: A Beginner’s Guide</a></li> <li><a href="https://everestforms.net/blog/wordpress-form-payment-option-paypal/" rel="nofollow ugc">How to Create a WordPress PayPal Payment Form?</a></li> </ul> <h3>Get in Touch with us</h3> <p>👉 <a href="https://www.facebook.com/groups/everestforms" rel="nofollow ugc">Facebook Group</a></p> <p>👉 <a href="https://twitter.com/everestforms" rel="nofollow ugc">Twitter</a></p> <p>👉 <a href="https://www.youtube.com/@EverestForms" rel="nofollow ugc">Youtube</a></p> <h3>Explore More Products from Our Team</h3> <p>Love Everest Forms? Why not check out more WordPress themes and plugins from us?</p> <ul> <li> <p><a href="https://masteriyo.com/" rel="nofollow ugc">Masteriyo</a> &#8211; A Powerful and Easy WordPress LMS Plugin.</p> </li> <li> <p><a href="https://wpuserregistration.com/" rel="nofollow ugc">User Registration &amp; Membership</a> &#8211; #1 Best WordPress User Registration &amp; Membership Plugin.</p> </li> <li> <p><a href="https://wpblockart.com/blockart-blocks/" rel="nofollow ugc">BlockArt Blocks</a> &#8211; Free Gutenberg Custom Blocks Plugin.</p> </li> <li> <p><a href="https://wpblockart.com/magazine-blocks/" rel="nofollow ugc">Magazine Blocks</a> &#8211; Gutenberg Blocks Plugin to Build Magazine-style Sites.</p> </li> <li> <p><a href="https://zakratheme.com/" rel="nofollow ugc">Zakra</a> &#8211; Best WordPress Multipurpose Theme Powering 60K+ Websites.</p> </li> <li> <p><a href="https://themegrill.com/" rel="nofollow ugc">ThemeGrill</a> &#8211; Beautiful Free WordPress Themes.</p> </li> </ul>
WordPress Plugin DirectoryWordPress Plugin Directory
7.58M