What is CVE-2026-13167?
CVE-2026-13167 is an authorization bypass vulnerability in the WordPress Everest Forms plugin (versions up to and including 3.5.2). The plugin fails to properly verify a user's authorization to perform certain actions. Updating to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-13167 WordPress Everest Forms plaginində (3.5.2 və aşağı versiyalar) avtorizasiya bypass zəifliyidir. Plugin istifadəçinin hər hansı əməliyyatı icra etmək səlahiyyətini düzgün yoxlamır. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which plugin does CVE-2026-13167 affect?
This vulnerability affects the WordPress Everest Forms plugin.
Which versions of the WordPress Everest Forms plugin are vulnerable to CVE-2026-13167?
Versions up to and including 3.5.2 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.