← WordPress Vulnerabilities
WordPress security by component

NEX-Forms – Ultimate Forms Plugin for WordPress

NEX-Forms – Ultimate Forms Plugin for WordPress (nex-forms-express-wp-form-builder) is a WordPress plugin with 36 published CVE records in this archive. The latest tracked vulnerability was published Sep 18, 2026; the highest published CVSS base score is 9.8.

Plugin slug: nex-forms-express-wp-form-builder

CVE-2026-75961: NEX-Forms – Ultimate Forms Plugin for WordPress: SQL injection bypasses form-report operator validation

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up to, and including, 9.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The operator allowlist applied by get_table_records() when building its own WHERE fragment is not enforced on the same tainted additional_params array when it is forwarded to get_total_records(), leaving the SQL sink unprotected. The minimum named role or capability behind custom-level access is not disclosed. Validation in one query builder does not protect the separate total-records sink. Affected versions reported by the CNA: <= 9.3.0. No fixed release is confirmed for this CVE in this review.

PublishedSep 18, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for nex-forms-express-wp-form-builder
Safe version
Sep 18, 2026 CVE-2026-75961
NEX-Forms – Ultimate Forms Plugin for WordPress: SQL injection bypasses form-report operator validation
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up to, and including, 9.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The operator allowlist applied by get_table_records() when building its own WHERE fragment is not enforced on the same tainted additional_params array when it is forwarded to get_total_records(), leaving the SQL sink unprotected. The minimum named role or capability behind custom-level access is not disclosed. Validation in one query builder does not protect the separate total-records sink. Affected versions reported by the CNA: <= 9.3.0. No fixed release is confirmed for this CVE in this review.
See mitigation notes
CVE4.9
NVDPending
Aug 16, 2026 CVE-2026-15602
NEX-Forms report parameters permit second-order SQL injection
NEX-Forms through 9.2.4 stores the additional_params value through submission_report2, which lacks a nonce and relies on a configurable capability that can be assigned as low as Subscriber. A later CSV export incorporates that stored value into SQL without adequate preparation, enabling second-order SQL injection and database extraction. The exact capability configuration, request action, export trigger, query, and payload are not disclosed.
See mitigation notes
CVE4.9
NVDPending
Aug 01, 2026 CVE-2026-15450
NEX-Forms database paths permit arbitrary server-file deletion
NEX-Forms through 9.2.3 lets an authorized user store an arbitrary location value through insert_record(); delete_file() later retrieves that value and passes it directly to unlink() without path validation. Administrators, or lower roles when the plugin's user-level option permits them, can traverse to and delete arbitrary files such as wp-config.php.
> 9.2.3
CVE8.1
NVDPending
Jul 17, 2026 CVE-2026-10525
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is < 9.2.3.
9.2.3
CVE6.1
NVDPending
Jul 13, 2026 CVE-2026-57668
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 9.2.2.
9.2.3
CVE7.1
NVDPending
Jul 11, 2026 CVE-2026-9017
NEX-Forms – Ultimate Forms Plugin for WordPress: A security weakness
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 9.2.2.
See mitigation notes
CVE5.3
NVDPending
Jul 03, 2026 CVE-2026-13040
NEX-Forms – Ultimate Forms Plugin for WordPress: Cross-site scripting
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 9.2.2.
See mitigation notes
CVE7.2
NVDPending
Jul 01, 2026 CVE-2026-12142
NEX-Forms – Ultimate Forms Plugin for WordPress: Cross-site scripting
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 9.2.2.
See mitigation notes
CVE7.2
NVDPending
Jun 27, 2026 CVE-2026-12404
NEX-Forms – Ultimate Forms Plugin for WordPress: A security weakness
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 9.2.2.
See mitigation notes
CVE5.3
NVDPending
May 15, 2026 CVE-2026-7046
NEX-Forms – Ultimate Forms Plugin for WordPress: SQL injection
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by SQL injection. Exploitation requires an authenticated administrator account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 9.1.12.
See mitigation notes
CVE4.9
NVDPending
Feb 20, 2026 CVE-2025-69326
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Feb 20, 2026 CVE-2025-69324
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Jan 31, 2026 CVE-2025-15510
NEX-Forms – Ultimate Forms: A security weakness
NEX-Forms – Ultimate Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jan 09, 2026 CVE-2025-14803
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.8
NVDPending
Aug 20, 2025 CVE-2025-49399
NEX-Forms: Cross-site request forgery
NEX-Forms is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVDPending
May 08, 2025 CVE-2025-4208
NEX-Forms – Ultimate Form Builder – Contact forms and much more: A security weakness
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.3
NVDPending
May 08, 2025 CVE-2025-3468
NEX-Forms – Ultimate Form Builder – Contact forms and much more: Cross-site scripting
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Dec 25, 2024 CVE-2024-10862
NEX-Forms – Ultimate Form Builder – Contact forms and much more: SQL injection
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE4.9
NVDPending
Dec 06, 2024 CVE-2024-53808
NEX-Forms: SQL injection
NEX-Forms is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVD7.2
Oct 05, 2024 CVE-2024-47389
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Jul 21, 2024 CVE-2024-37512
NEX-Forms – Ultimate Form Builder: Cross-site scripting
NEX-Forms – Ultimate Form Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 15, 2024 CVE-2024-25593
NEX-Forms – Ultimate Form Builder: Cross-site scripting
NEX-Forms – Ultimate Form Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Feb 29, 2024 CVE-2024-1130
NEX-Forms – Ultimate Form Builder – Contact forms and much more: A security weakness
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD4.3
Feb 29, 2024 CVE-2024-1129
NEX-Forms – Ultimate Form Builder – Contact forms and much more: A security weakness
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD4.3
Feb 29, 2024 CVE-2024-0907
NEX-Forms – Ultimate Form Builder – Contact forms and much more: A security weakness
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD4.3
Jan 05, 2024 CVE-2023-52120
NEX-Forms – Ultimate Form Builder – Contact forms and much more: Cross-site request forgery
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Dec 28, 2023 CVE-2023-50838
NEX-Forms – Ultimate Form Builder – Contact forms and much more: SQL injection
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVD7.2
Jul 17, 2023 CVE-2023-0439
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.4
May 08, 2023 CVE-2023-2114
NEX-Forms: A security weakness
NEX-Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.2
NVD7.2
Mar 27, 2023 CVE-2023-0272
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Mar 07, 2023 CVE-2020-36670
NEX-Forms: A security weakness
NEX-Forms is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.3
NVD6.3
Sep 19, 2022 CVE-2022-3142
NEX-Forms: SQL injection
NEX-Forms is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVEPending
NVD8.8
Dec 13, 2021 CVE-2021-24705
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.8
Jul 19, 2021 CVE-2021-34676
Nex Forms Express Wp Form Builder: Privilege escalation or authentication bypass
Nex Forms Express Wp Form Builder is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVEPending
NVD7.5
Jul 19, 2021 CVE-2021-34675
Nex Forms Express Wp Form Builder: Privilege escalation or authentication bypass
Nex Forms Express Wp Form Builder is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVEPending
NVD7.5
Oct 07, 2019 CVE-2015-9452
Nex Forms Express Wp Form Builder: SQL injection
Nex Forms Express Wp Form Builder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVEPending
NVD9.8