← WordPress Vulnerabilities
WordPress security by component

NEX-Forms – Ultimate Forms Plugin for WordPress

NEX-Forms – Ultimate Forms Plugin for WordPress is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published May 03, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: nex-forms-ultimate-forms

CVE-2026-5063: NEX-Forms – Ultimate Forms Plugin for WordPress: Cross-site scripting

NEX-Forms – Ultimate Forms Plugin for WordPress is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 9.1.11.

PublishedMay 03, 2026
Known safe version> 9.1.11
Safe version
May 03, 2026 CVE-2026-5063
NEX-Forms – Ultimate Forms Plugin for WordPress: Cross-site scripting
NEX-Forms – Ultimate Forms Plugin for WordPress is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 9.1.11.
> 9.1.11
CVE7.2
NVDPending
Mar 16, 2026 CVE-2026-1948
NEX-Forms – Ultimate Forms Plugin for: A security weakness
NEX-Forms – Ultimate Forms Plugin for is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Mar 16, 2026 CVE-2026-1947
NEX-Forms – Ultimate Forms Plugin for: A security weakness
NEX-Forms – Ultimate Forms Plugin for is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Oct 11, 2025 CVE-2025-10185
NEX-Forms – Ultimate Forms Plugin for: SQL injection
NEX-Forms – Ultimate Forms Plugin for is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE4.9
NVDPending