Extension WordPress
Vulnérabilités NEX-Forms – Ultimate Forms Plugin for WordPress
Cette page rassemble les failles publiées pour NEX-Forms – Ultimate Forms Plugin for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de NEX-Forms – Ultimate Forms Plugin for WordPress
37 fiches
NEX-Forms <= 9.2.2 – Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_send_nf_email AJAX Action
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized…
*-9.2.2
9.2.3
10/07/2026
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.2.2 – Unauthenticated Stored Cross-Site Scripting
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-9.2.2
9.2.3
10/07/2026
NEX-Forms <= 9.2.2 – Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameter
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This…
*-9.2.2
9.2.3
02/07/2026
NEX-Forms <= 9.2.2 – Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '_name[]' Array Parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This…
*-9.2.2
9.2.3
30/06/2026
NEX-Forms <= 9.2.2 – Missing Authorization to Unauthenticated Sensitive Information Disclosure via CSVExport Class
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized…
*-9.2.2
9.2.3
26/06/2026
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.12 – Authenticated (Administrator+) SQL Injection via 'table' Parameter
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'table' parameter in all versions up to, and including, 9.1.12 due to insufficient escaping on the user supplied…
*-9.1.12
9.1.13
14/05/2026
NEX-Forms <= 9.1.11 – Unauthenticated Stored Cross-Site Scripting via POST Parameter Key Names
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via POST parameter key names in the submit_nex_form() function in versions up to, and including, 9.1.11 due to insufficient input sanitization…
*-9.1.11
9.1.12
02/05/2026
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 – Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_id
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 9.1.9 via the submit_nex_form() function due to missing validation on a user controlled…
*-9.1.9
9.1.10
14/03/2026
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 – Missing Authorization to Authenticated (Subscriber+) License Deactivation via deactivate_license
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_license() function in all versions up to, and including, 9.1.9. This makes…
*-9.1.9
9.1.10
13/03/2026
NEX-Forms <= 9.1.7 – Reflected Cross-Site Scripting
The NEX-Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 9.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-9.1.7
9.1.8
09/02/2026
NEX-Forms <= 9.1.7 – Unauthenticated Stored Cross-Site Scripting
The NEX-Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-9.1.7
9.1.8
04/02/2026
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.8 – Missing Authorization to Unauthenticated Sensitive Information Exposure
The NEX-Forms – Ultimate Forms Plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the NF5_Export_Forms class constructor in all versions up to, and including, 9.1.8. This makes it possible…
*-9.1.8
9.1.9
30/01/2026
Nex-Forms Express WP Form Builder <= 9.1.7 – Authenticated (Admin+) Stored Cross-Site Scripting
The Nex-Forms Express WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-9.1.7
9.1.8
19/12/2025
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.6 – Authenticated (Admin+) SQL Injection
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in the action nf_load_form_entries in all versions up to, and including, 9.1.6 due to insufficient escaping on the…
*-9.1.6
9.1.7
10/10/2025
NEX-Forms <= 9.1.3 – Cross-Site Request Forgery
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.1.3. This is due to missing or incorrect nonce validation on a function. This…
*-9.1.3
9.1.4
20/08/2025
NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 – Authenticated (Custom) Limited Code Execution via get_table_records Function
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Limited Code Execution in all versions up to, and including, 8.9.1 via the get_table_records function. This is due to the…
*-8.9.1
8.9.2
07/05/2025
NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 – Authenticated (Custom) Stored Cross-Site Scripting
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the clean_html and form_fields parameters in all versions up to, and including, 8.9.1 due to insufficient…
*-8.9.1
8.9.2
07/05/2025
NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.8.1 – Unauthenticated Sensitive Information Exposure
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.8.1 via file uploads due to insufficient directory listing prevention…
*-8.8.1
8.8.2
11/03/2025
NEX-Forms <= 8.7.15 – Authenticated (Admin+) SQL Injection
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to SQL Injection via the 'search_params' parameter in all versions up to, and including, 8.7.15 due to insufficient escaping on the…
*-8.7.15
8.7.16
24/12/2024
NEX-Forms – Ultimate Form Builder <= 8.7.8 – Authenticated (Administrator+) SQL Injection
The NEX-Forms – Ultimate Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
*-8.7.8
8.7.9
02/12/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.