NEX-Forms – Ultimate Forms Plugin for WordPress
NEX-Forms – Ultimate Forms Plugin for WordPress (nex-forms-express-wp-form-builder) is a WordPress plugin with 36 published CVE records in this archive. The latest tracked vulnerability was published Sep 18, 2026; the highest published CVSS base score is 9.8.
nex-forms-express-wp-form-builderCVE-2026-75961: NEX-Forms – Ultimate Forms Plugin for WordPress: SQL injection bypasses form-report operator validation
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up to, and including, 9.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The operator allowlist applied by get_table_records() when building its own WHERE fragment is not enforced on the same tainted additional_params array when it is forwarded to get_total_records(), leaving the SQL sink unprotected. The minimum named role or capability behind custom-level access is not disclosed. Validation in one query builder does not protect the separate total-records sink. Affected versions reported by the CNA: <= 9.3.0. No fixed release is confirmed for this CVE in this review.
| Safe version |
|
||
|---|---|---|---|
| Sep 18, 2026 |
CVE-2026-75961
NEX-Forms – Ultimate Forms Plugin for WordPress: SQL injection bypasses form-report operator validation
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up to, and including, 9.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The operator allowlist applied by get_table_records() when building its own WHERE fragment is not enforced on the same tainted additional_params array when it is forwarded to get_total_records(), leaving the SQL sink unprotected. The minimum named role or capability behind custom-level access is not disclosed. Validation in one query builder does not protect the separate total-records sink. Affected versions reported by the CNA: <= 9.3.0. No fixed release is confirmed for this CVE in this review.
|
See mitigation notes |
CVE4.9
NVDPending
|
| Aug 16, 2026 |
CVE-2026-15602
NEX-Forms report parameters permit second-order SQL injection
NEX-Forms through 9.2.4 stores the additional_params value through submission_report2, which lacks a nonce and relies on a configurable capability that can be assigned as low as Subscriber. A later CSV export incorporates that stored value into SQL without adequate preparation, enabling second-order SQL injection and database extraction. The exact capability configuration, request action, export trigger, query, and payload are not disclosed.
|
See mitigation notes |
CVE4.9
NVDPending
|
| Aug 01, 2026 |
CVE-2026-15450
NEX-Forms database paths permit arbitrary server-file deletion
NEX-Forms through 9.2.3 lets an authorized user store an arbitrary location value through insert_record(); delete_file() later retrieves that value and passes it directly to unlink() without path validation. Administrators, or lower roles when the plugin's user-level option permits them, can traverse to and delete arbitrary files such as wp-config.php.
|
> 9.2.3 |
CVE8.1
NVDPending
|
| Jul 17, 2026 |
CVE-2026-10525
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is < 9.2.3.
|
9.2.3 |
CVE6.1
NVDPending
|
| Jul 13, 2026 |
CVE-2026-57668
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 9.2.2.
|
9.2.3 |
CVE7.1
NVDPending
|
| Jul 11, 2026 |
CVE-2026-9017
NEX-Forms – Ultimate Forms Plugin for WordPress: A security weakness
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 9.2.2.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jul 03, 2026 |
CVE-2026-13040
NEX-Forms – Ultimate Forms Plugin for WordPress: Cross-site scripting
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 9.2.2.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Jul 01, 2026 |
CVE-2026-12142
NEX-Forms – Ultimate Forms Plugin for WordPress: Cross-site scripting
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 9.2.2.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Jun 27, 2026 |
CVE-2026-12404
NEX-Forms – Ultimate Forms Plugin for WordPress: A security weakness
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 9.2.2.
|
See mitigation notes |
CVE5.3
NVDPending
|
| May 15, 2026 |
CVE-2026-7046
NEX-Forms – Ultimate Forms Plugin for WordPress: SQL injection
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by SQL injection. Exploitation requires an authenticated administrator account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 9.1.12.
|
See mitigation notes |
CVE4.9
NVDPending
|
| Feb 20, 2026 |
CVE-2025-69326
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Feb 20, 2026 |
CVE-2025-69324
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Jan 31, 2026 |
CVE-2025-15510
NEX-Forms – Ultimate Forms: A security weakness
NEX-Forms – Ultimate Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jan 09, 2026 |
CVE-2025-14803
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.8
NVDPending
|
| Aug 20, 2025 |
CVE-2025-49399
NEX-Forms: Cross-site request forgery
NEX-Forms is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE8.8
NVDPending
|
| May 08, 2025 |
CVE-2025-4208
NEX-Forms – Ultimate Form Builder – Contact forms and much more: A security weakness
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.3
NVDPending
|
| May 08, 2025 |
CVE-2025-3468
NEX-Forms – Ultimate Form Builder – Contact forms and much more: Cross-site scripting
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Dec 25, 2024 |
CVE-2024-10862
NEX-Forms – Ultimate Form Builder – Contact forms and much more: SQL injection
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE4.9
NVDPending
|
| Dec 06, 2024 |
CVE-2024-53808
NEX-Forms: SQL injection
NEX-Forms is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVD7.2
|
| Oct 05, 2024 |
CVE-2024-47389
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Jul 21, 2024 |
CVE-2024-37512
NEX-Forms – Ultimate Form Builder: Cross-site scripting
NEX-Forms – Ultimate Form Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Mar 15, 2024 |
CVE-2024-25593
NEX-Forms – Ultimate Form Builder: Cross-site scripting
NEX-Forms – Ultimate Form Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Feb 29, 2024 |
CVE-2024-1130
NEX-Forms – Ultimate Form Builder – Contact forms and much more: A security weakness
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD4.3
|
| Feb 29, 2024 |
CVE-2024-1129
NEX-Forms – Ultimate Form Builder – Contact forms and much more: A security weakness
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD4.3
|
| Feb 29, 2024 |
CVE-2024-0907
NEX-Forms – Ultimate Form Builder – Contact forms and much more: A security weakness
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD4.3
|
| Jan 05, 2024 |
CVE-2023-52120
NEX-Forms – Ultimate Form Builder – Contact forms and much more: Cross-site request forgery
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Dec 28, 2023 |
CVE-2023-50838
NEX-Forms – Ultimate Form Builder – Contact forms and much more: SQL injection
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVD7.2
|
| Jul 17, 2023 |
CVE-2023-0439
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD5.4
|
| May 08, 2023 |
CVE-2023-2114
NEX-Forms: A security weakness
NEX-Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Mar 27, 2023 |
CVE-2023-0272
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Mar 07, 2023 |
CVE-2020-36670
NEX-Forms: A security weakness
NEX-Forms is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.3
NVD6.3
|
| Sep 19, 2022 |
CVE-2022-3142
NEX-Forms: SQL injection
NEX-Forms is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Dec 13, 2021 |
CVE-2021-24705
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.8
|
| Jul 19, 2021 |
CVE-2021-34676
Nex Forms Express Wp Form Builder: Privilege escalation or authentication bypass
Nex Forms Express Wp Form Builder is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVEPending
NVD7.5
|
| Jul 19, 2021 |
CVE-2021-34675
Nex Forms Express Wp Form Builder: Privilege escalation or authentication bypass
Nex Forms Express Wp Form Builder is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVEPending
NVD7.5
|
| Oct 07, 2019 |
CVE-2015-9452
Nex Forms Express Wp Form Builder: SQL injection
Nex Forms Express Wp Form Builder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD9.8
|