100,000 WordPress Sites Affected by Arbitrary File Upload, Read and Deletion Vulnerability in Everest Forms WordPress Plugin
Wordfence's Bug Bounty Program rewards researchers up to $31,200 for identifying vulnerabilities. On January 16, 2025, a critical Arbitrary File Upload vulnerability was found in the Everest Forms plugin, allowing unauthenticated attackers to compromise sites by uploading malicious files. The researcher, Arkadiusz Hydzik, received a $4,290 bounty. A patch (version 3.0.9.5) was released on February 20, 2025, with firewall rules implemented for premium users on February 13, 2025, and for free users on March 15, 2025. Users are urged to update to the latest version for security.