A WordPress plugin vulnerability allows authenticated users with subscriber-level access or higher to permanently delete arbitrary media attachments belonging to other users, including administrators. The issue stems from missing ownership validation on user-controlled attachment IDs in the User Registration & Membership plugin. The vulnerability was disclosed on 2026-05-28 with a CVSS 3.1 score of 5.3 (M [truncated]
The Everest Forms WordPress plugin is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function. This allows authenticated attackers with Subscriber-level access and above to send test emails to arbitrary addresses from the server. The vulnerability affects all versions up to and including 3.4.7. The issue was disclosed on 2026-05-28 and has a CVSS 3.1 sc [truncated]
The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling PHP's native unserialize() on stored entry meta values without passing the allowed_classes parameter. This vulnerability allows unauthenticated attackers to [truncated]