← WordPress Vulnerabilities
WordPress security by component

NEX-Forms – Ultimate Forms Plugin for WordPress

Build beautiful responsive forms for WordPress. Contact forms, surveys, quizzes, booking forms, payments, popups & more with NEX-Forms...

Plugin slug: nex-forms-express-wp-form-builder · Description source: WordPress.org

CVE-2026-10525: NEX-Forms: Cross-site scripting

NEX-Forms is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is < 9.2.3.

PublishedJul 17, 2026
Known safe version9.2.3
Safe version
Jul 17, 2026 CVE-2026-10525
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is < 9.2.3.
9.2.3
CVE6.1
NVDPending
Jul 13, 2026 CVE-2026-57668
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 9.2.2.
9.2.3
CVE7.1
NVDPending
Jul 11, 2026 CVE-2026-9017
NEX-Forms – Ultimate Forms Plugin for WordPress: A security weakness
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 9.2.2.
> 9.2.2
CVE5.3
NVDPending
Jul 03, 2026 CVE-2026-13040
NEX-Forms – Ultimate Forms Plugin for WordPress: Cross-site scripting
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 9.2.2.
> 9.2.2
CVE7.2
NVDPending
Jul 01, 2026 CVE-2026-12142
NEX-Forms – Ultimate Forms Plugin for WordPress: Cross-site scripting
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 9.2.2.
> 9.2.2
CVE7.2
NVDPending
Jun 27, 2026 CVE-2026-12404
NEX-Forms – Ultimate Forms Plugin for WordPress: A security weakness
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 9.2.2.
> 9.2.2
CVE5.3
NVDPending
May 15, 2026 CVE-2026-7046
NEX-Forms – Ultimate Forms Plugin for WordPress: SQL injection
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 9.1.12.
> 9.1.12
CVE4.9
NVDPending
Feb 20, 2026 CVE-2025-69326
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Feb 20, 2026 CVE-2025-69324
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Jan 31, 2026 CVE-2025-15510
NEX-Forms – Ultimate Forms: A security weakness
NEX-Forms – Ultimate Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jan 09, 2026 CVE-2025-14803
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.8
NVDPending
Aug 20, 2025 CVE-2025-49399
NEX-Forms: Cross-site request forgery
NEX-Forms is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVDPending
May 08, 2025 CVE-2025-4208
NEX-Forms – Ultimate Form Builder – Contact forms and much more: A security weakness
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.3
NVDPending
May 08, 2025 CVE-2025-3468
NEX-Forms – Ultimate Form Builder – Contact forms and much more: Cross-site scripting
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Dec 25, 2024 CVE-2024-10862
NEX-Forms – Ultimate Form Builder – Contact forms and much more: SQL injection
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE4.9
NVDPending
Dec 06, 2024 CVE-2024-53808
NEX-Forms: SQL injection
NEX-Forms is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVD7.2
Oct 05, 2024 CVE-2024-47389
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Jul 21, 2024 CVE-2024-37512
NEX-Forms – Ultimate Form Builder: Cross-site scripting
NEX-Forms – Ultimate Form Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Mar 15, 2024 CVE-2024-25593
NEX-Forms – Ultimate Form Builder: Cross-site scripting
NEX-Forms – Ultimate Form Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Feb 29, 2024 CVE-2024-1130
NEX-Forms – Ultimate Form Builder – Contact forms and much more: A security weakness
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD4.3
Feb 29, 2024 CVE-2024-1129
NEX-Forms – Ultimate Form Builder – Contact forms and much more: A security weakness
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD4.3
Feb 29, 2024 CVE-2024-0907
NEX-Forms – Ultimate Form Builder – Contact forms and much more: A security weakness
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD4.3
Jan 05, 2024 CVE-2023-52120
NEX-Forms – Ultimate Form Builder – Contact forms and much more: Cross-site request forgery
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Dec 28, 2023 CVE-2023-50838
NEX-Forms – Ultimate Form Builder – Contact forms and much more: SQL injection
NEX-Forms – Ultimate Form Builder – Contact forms and much more is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVD7.2
Jul 17, 2023 CVE-2023-0439
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
May 08, 2023 CVE-2023-2114
NEX-Forms: A security weakness
NEX-Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.2
NVD7.2
Mar 27, 2023 CVE-2023-0272
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Mar 07, 2023 CVE-2020-36670
NEX-Forms: A security weakness
NEX-Forms is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.3
NVD6.3
Sep 19, 2022 CVE-2022-3142
NEX-Forms: SQL injection
NEX-Forms is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8
Dec 13, 2021 CVE-2021-24705
NEX-Forms: Cross-site scripting
NEX-Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jul 19, 2021 CVE-2021-34676
Nex Forms Express Wp Form Builder: Privilege escalation or authentication bypass
Nex Forms Express Wp Form Builder is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE7.5
NVD7.5
Jul 19, 2021 CVE-2021-34675
Nex Forms Express Wp Form Builder: Privilege escalation or authentication bypass
Nex Forms Express Wp Form Builder is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE7.5
NVD7.5
Oct 07, 2019 CVE-2015-9452
Nex Forms Express Wp Form Builder: SQL injection
Nex Forms Express Wp Form Builder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8