Known vulnerabilities in the NEX-Forms – Ultimate Forms Plugin for WordPress plugin
10 security advisories have been published for the NEX-Forms – Ultimate Forms Plugin for WordPress plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- NEX-Forms – Ultimate Forms Plugin for WordPress - SQL Injection (CVE-2026-15602) MEDIUM
- NEX-Forms – Ultimate Forms Plugin for WordPress - Path Traversal (CVE-2026-15450) HIGH
- NEX-Forms – Ultimate Forms Plugin for WordPress - Broken Access Control (CVE-2026-9017) MEDIUM
- NEX-Forms – Ultimate Forms Plugin for WordPress - Cross-Site Scripting (XSS) (CVE-2026-13040) HIGH
- NEX-Forms – Ultimate Forms Plugin for WordPress - Cross-Site Scripting (XSS) (CVE-2026-12142) HIGH
- NEX-Forms – Ultimate Forms Plugin for WordPress - Broken Access Control (CVE-2026-12404) MEDIUM
- NEX-Forms – Ultimate Forms Plugin for WordPress - SQL Injection (CVE-2026-7046) MEDIUM
- NEX-Forms – Ultimate Forms Plugin for WordPress - Cross-Site Scripting (XSS) (CVE-2026-5063) HIGH
- NEX-Forms – Ultimate Forms Plugin for WordPress - Security Vulnerability (CVE-2026-1947) HIGH
- NEX-Forms – Ultimate Forms Plugin for WordPress - Broken Access Control (CVE-2026-1948) MEDIUM