WordPress security by component
NEX-Forms – Ultimate Forms Plugin for WordPress
Plugin description
Build beautiful responsive forms for WordPress. Contact forms, surveys, quizzes, booking forms, payments, popups & more with NEX-Forms...
Plugin slug:
nex-forms-express-wp-form-builder · Description source: WordPress.orgLatest vulnerability
CVE-2026-10525: NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is < 9.2.3.
| Safe version |
|
||
|---|---|---|---|
| Jul 17, 2026 |
CVE-2026-10525
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is < 9.2.3.
|
9.2.3 |
CVE6.1
NVDPending
|
| Jul 13, 2026 |
CVE-2026-57668
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 9.2.2.
|
9.2.3 |
CVE7.1
NVDPending
|
| Jul 11, 2026 |
CVE-2026-9017
NEX-Forms – Ultimate Forms Plugin for WordPress: A security weakness
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 9.2.2.
|
> 9.2.2 |
CVE5.3
NVDPending
|
| Jul 03, 2026 |
CVE-2026-13040
NEX-Forms – Ultimate Forms Plugin for WordPress: Cross-site scripting
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 9.2.2.
|
> 9.2.2 |
CVE7.2
NVDPending
|
| Jul 01, 2026 |
CVE-2026-12142
NEX-Forms – Ultimate Forms Plugin for WordPress: Cross-site scripting
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 9.2.2.
|
> 9.2.2 |
CVE7.2
NVDPending
|
| Jun 27, 2026 |
CVE-2026-12404
NEX-Forms – Ultimate Forms Plugin for WordPress: A security weakness
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 9.2.2.
|
> 9.2.2 |
CVE5.3
NVDPending
|
| May 15, 2026 |
CVE-2026-7046
NEX-Forms – Ultimate Forms Plugin for WordPress: SQL injection
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 9.1.12.
|
> 9.1.12 |
CVE4.9
NVDPending
|
| Feb 20, 2026 |
CVE-2025-69326
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Feb 20, 2026 |
CVE-2025-69324
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Jan 31, 2026 |
CVE-2025-15510
NEX-Forms – Ultimate Forms: A security weakness
NEX-Forms – Ultimate Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jan 09, 2026 |
CVE-2025-14803
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.8
NVDPending
|
| Aug 20, 2025 |
CVE-2025-49399
NEX-Forms: Cross-site request forgery
NEX-Forms is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE8.8
NVDPending
|
| May 08, 2025 |
CVE-2025-4208
NEX-Forms – Ultimate Form Builder – Contact forms and much more: A security weakness
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.3
NVDPending
|
| May 08, 2025 |
CVE-2025-3468
NEX-Forms – Ultimate Form Builder – Contact forms and much more: Cross-site scripting
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Dec 25, 2024 |
CVE-2024-10862
NEX-Forms – Ultimate Form Builder – Contact forms and much more: SQL injection
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE4.9
NVDPending
|
| Dec 06, 2024 |
CVE-2024-53808
NEX-Forms: SQL injection
NEX-Forms is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVD7.2
|
| Oct 05, 2024 |
CVE-2024-47389
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Jul 21, 2024 |
CVE-2024-37512
NEX-Forms – Ultimate Form Builder: Cross-site scripting
NEX-Forms – Ultimate Form Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Mar 15, 2024 |
CVE-2024-25593
NEX-Forms – Ultimate Form Builder: Cross-site scripting
NEX-Forms – Ultimate Form Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Feb 29, 2024 |
CVE-2024-1130
NEX-Forms – Ultimate Form Builder – Contact forms and much more: A security weakness
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD4.3
|
| Feb 29, 2024 |
CVE-2024-1129
NEX-Forms – Ultimate Form Builder – Contact forms and much more: A security weakness
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD4.3
|
| Feb 29, 2024 |
CVE-2024-0907
NEX-Forms – Ultimate Form Builder – Contact forms and much more: A security weakness
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD4.3
|
| Jan 05, 2024 |
CVE-2023-52120
NEX-Forms – Ultimate Form Builder – Contact forms and much more: Cross-site request forgery
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Dec 28, 2023 |
CVE-2023-50838
NEX-Forms – Ultimate Form Builder – Contact forms and much more: SQL injection
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVD7.2
|
| Jul 17, 2023 |
CVE-2023-0439
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| May 08, 2023 |
CVE-2023-2114
NEX-Forms: A security weakness
NEX-Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Mar 27, 2023 |
CVE-2023-0272
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Mar 07, 2023 |
CVE-2020-36670
NEX-Forms: A security weakness
NEX-Forms is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.3
NVD6.3
|
| Sep 19, 2022 |
CVE-2022-3142
NEX-Forms: SQL injection
NEX-Forms is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Dec 13, 2021 |
CVE-2021-24705
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Jul 19, 2021 |
CVE-2021-34676
Nex Forms Express Wp Form Builder: Privilege escalation or authentication bypass
Nex Forms Express Wp Form Builder is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Jul 19, 2021 |
CVE-2021-34675
Nex Forms Express Wp Form Builder: Privilege escalation or authentication bypass
Nex Forms Express Wp Form Builder is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Oct 07, 2019 |
CVE-2015-9452
Nex Forms Express Wp Form Builder: SQL injection
Nex Forms Express Wp Form Builder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|