NEX-Forms – Ultimate Forms Plugin for WordPress

Information

Software Type Plugin
Software Slug nex-forms-express-wp-form-builder (view on wordpress.org)
Software Status Active
Software Author webaways
Software Website basixonline.net
Software Downloads 530,623
Software Active Installs 6,000
Software Record Last Updated July 21, 2026

Showing 1-20 of 37 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_send_nf_email AJAX Action Patched CVE-2026-9017 5.3 Michael Iden (Mickhat) July 10, 2026
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting Patched CVE-2026-57668 7.2 Nguyen Ba Khanh July 10, 2026
NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameter Patched CVE-2026-13040 7.2 Taichi Kashimura July 2, 2026
NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter Patched CVE-2026-12142 7.2 Anthony Cihan (Hann1bl3L3ct3r) June 30, 2026
NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via CSVExport Class Patched CVE-2026-12404 5.3 valent1 June 26, 2026
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.12 - Authenticated (Administrator+) SQL Injection via 'table' Parameter Patched CVE-2026-7046 4.9 Athul Jayaram May 14, 2026
NEX-Forms <= 9.1.11 - Unauthenticated Stored Cross-Site Scripting via POST Parameter Key Names Patched CVE-2026-5063 7.2 Naoya Takahashi (nakko) May 2, 2026
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_id Patched CVE-2026-1947 7.5 Youssef Elouaer March 14, 2026
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Authenticated (Subscriber+) License Deactivation via deactivate_license Patched CVE-2026-1948 4.3 Legion Hunter March 13, 2026
NEX-Forms <= 9.1.7 - Reflected Cross-Site Scripting Patched CVE-2025-69326 6.1 Skalucy February 9, 2026
NEX-Forms <= 9.1.7 - Unauthenticated Stored Cross-Site Scripting Patched CVE-2025-69324 7.2 Jarno Vos (jarnovos) February 4, 2026
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.8 - Missing Authorization to Unauthenticated Sensitive Information Exposure Patched CVE-2025-15510 5.3 Deadbee January 30, 2026
Nex-Forms Express WP Form Builder <= 9.1.7 - Authenticated (Admin+) Stored Cross-Site Scripting Patched CVE-2025-14803 4.4 Vuln Seeker Cyber Security Team December 19, 2025
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.6 - Authenticated (Admin+) SQL Injection Patched CVE-2025-10185 4.9 dutafi October 10, 2025
NEX-Forms <= 9.1.3 - Cross-Site Request Forgery Patched CVE-2025-49399 4.3 Ananda Dhakal August 20, 2025
NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) Limited Code Execution via get_table_records Function Patched CVE-2025-4208 6.3 m3ssap0 May 7, 2025
NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) Stored Cross-Site Scripting Patched CVE-2025-3468 6.4 m3ssap0 May 7, 2025
NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.8.1 - Unauthenticated Sensitive Information Exposure Patched CVE-2024-13498 5.3 Tim Coen March 11, 2025
NEX-Forms <= 8.7.15 - Authenticated (Admin+) SQL Injection Patched CVE-2024-10862 4.9 M.Awad December 24, 2024
NEX-Forms – Ultimate Form Builder <= 8.7.8 - Authenticated (Administrator+) SQL Injection Patched CVE-2024-53808 4.9 trongnb02 December 2, 2024

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation