Extension WordPress

Vulnérabilités NEX-Forms – Ultimate Forms Plugin for WordPress

Cette page rassemble les failles publiées pour NEX-Forms – Ultimate Forms Plugin for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.

37Vulnérabilités
2Critiques
37Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de NEX-Forms – Ultimate Forms Plugin for WordPress

37 fiches

CVE-2026-9017 Moyenne · 5,3
NEX-Forms – Ultimate Forms Plugin for WordPress

NEX-Forms <= 9.2.2 – Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_send_nf_email AJAX Action

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized…

Versions affectées

*-9.2.2

Correctif

9.2.3

Publication

10/07/2026

CVE-2026-57668 Élevée · 7,2
NEX-Forms – Ultimate Forms Plugin for WordPress

NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.2.2 – Unauthenticated Stored Cross-Site Scripting

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-9.2.2

Correctif

9.2.3

Publication

10/07/2026

CVE-2026-13040 Élevée · 7,2
NEX-Forms – Ultimate Forms Plugin for WordPress

NEX-Forms <= 9.2.2 – Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameter

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-9.2.2

Correctif

9.2.3

Publication

02/07/2026

CVE-2026-12142 Élevée · 7,2
NEX-Forms – Ultimate Forms Plugin for WordPress

NEX-Forms <= 9.2.2 – Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '_name[]' Array Parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-9.2.2

Correctif

9.2.3

Publication

30/06/2026

CVE-2026-12404 Moyenne · 5,3
NEX-Forms – Ultimate Forms Plugin for WordPress

NEX-Forms <= 9.2.2 – Missing Authorization to Unauthenticated Sensitive Information Disclosure via CSVExport Class

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized…

Versions affectées

*-9.2.2

Correctif

9.2.3

Publication

26/06/2026

CVE-2026-7046 Moyenne · 4,9
NEX-Forms – Ultimate Forms Plugin for WordPress

NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.12 – Authenticated (Administrator+) SQL Injection via 'table' Parameter

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'table' parameter in all versions up to, and including, 9.1.12 due to insufficient escaping on the user supplied…

Versions affectées

*-9.1.12

Correctif

9.1.13

Publication

14/05/2026

CVE-2026-5063 Élevée · 7,2
NEX-Forms – Ultimate Forms Plugin for WordPress

NEX-Forms <= 9.1.11 – Unauthenticated Stored Cross-Site Scripting via POST Parameter Key Names

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via POST parameter key names in the submit_nex_form() function in versions up to, and including, 9.1.11 due to insufficient input sanitization…

Versions affectées

*-9.1.11

Correctif

9.1.12

Publication

02/05/2026

CVE-2026-1947 Élevée · 7,5
NEX-Forms – Ultimate Forms Plugin for WordPress

NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 – Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_id

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 9.1.9 via the submit_nex_form() function due to missing validation on a user controlled…

Versions affectées

*-9.1.9

Correctif

9.1.10

Publication

14/03/2026

CVE-2026-1948 Moyenne · 4,3
NEX-Forms – Ultimate Forms Plugin for WordPress

NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 – Missing Authorization to Authenticated (Subscriber+) License Deactivation via deactivate_license

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_license() function in all versions up to, and including, 9.1.9. This makes…

Versions affectées

*-9.1.9

Correctif

9.1.10

Publication

13/03/2026

CVE-2025-69324 Élevée · 7,2
NEX-Forms – Ultimate Forms Plugin for WordPress

NEX-Forms <= 9.1.7 – Unauthenticated Stored Cross-Site Scripting

The NEX-Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…

Versions affectées

*-9.1.7

Correctif

9.1.8

Publication

04/02/2026

CVE-2025-15510 Moyenne · 5,3
NEX-Forms – Ultimate Forms Plugin for WordPress

NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.8 – Missing Authorization to Unauthenticated Sensitive Information Exposure

The NEX-Forms – Ultimate Forms Plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the NF5_Export_Forms class constructor in all versions up to, and including, 9.1.8. This makes it possible…

Versions affectées

*-9.1.8

Correctif

9.1.9

Publication

30/01/2026

CVE-2025-14803 Moyenne · 4,4
NEX-Forms – Ultimate Forms Plugin for WordPress

Nex-Forms Express WP Form Builder <= 9.1.7 – Authenticated (Admin+) Stored Cross-Site Scripting

The Nex-Forms Express WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-9.1.7

Correctif

9.1.8

Publication

19/12/2025

CVE-2025-10185 Moyenne · 4,9
NEX-Forms – Ultimate Forms Plugin for WordPress

NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.6 – Authenticated (Admin+) SQL Injection

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in the action nf_load_form_entries in all versions up to, and including, 9.1.6 due to insufficient escaping on the…

Versions affectées

*-9.1.6

Correctif

9.1.7

Publication

10/10/2025

CVE-2025-4208 Moyenne · 6,3
NEX-Forms – Ultimate Forms Plugin for WordPress

NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 – Authenticated (Custom) Limited Code Execution via get_table_records Function

The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Limited Code Execution in all versions up to, and including, 8.9.1 via the get_table_records function. This is due to the…

Versions affectées

*-8.9.1

Correctif

8.9.2

Publication

07/05/2025

CVE-2025-3468 Moyenne · 6,4
NEX-Forms – Ultimate Forms Plugin for WordPress

NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 – Authenticated (Custom) Stored Cross-Site Scripting

The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the clean_html and form_fields parameters in all versions up to, and including, 8.9.1 due to insufficient…

Versions affectées

*-8.9.1

Correctif

8.9.2

Publication

07/05/2025

CVE-2024-13498 Moyenne · 5,3
NEX-Forms – Ultimate Forms Plugin for WordPress

NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.8.1 – Unauthenticated Sensitive Information Exposure

The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.8.1 via file uploads due to insufficient directory listing prevention…

Versions affectées

*-8.8.1

Correctif

8.8.2

Publication

11/03/2025

CVE-2024-53808 Moyenne · 4,9
NEX-Forms – Ultimate Forms Plugin for WordPress

NEX-Forms – Ultimate Form Builder <= 8.7.8 – Authenticated (Administrator+) SQL Injection

The NEX-Forms – Ultimate Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

Versions affectées

*-8.7.8

Correctif

8.7.9

Publication

02/12/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités