Junglewise Threat Intelligence

CVE-2026-12142: webaways NEX-Forms Stored XSS via _name[] parameter

CVE-2026-12142 · Severity: high · CVSS 7.2 · Published 2026-07-01

Technologies: Webaways NEX-Forms – Ultimate Forms Plugin for WordPress. Vendors: Webaways.

Executive brief

NEX-Forms is a WordPress plugin used to create and manage web forms. A security flaw allows unauthenticated attackers to inject malicious scripts into the website via form parameters. These scripts execute in the browser of any user who visits the affected page, potentially leading to unauthorized actions or data theft.

Technical details

NEX-Forms for WordPress (up to version 9.2.2) is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping of the '_name[]' array parameter. The vulnerability is exacerbated because the plugin's custom filtering function, NEXForms_allowed_tags(), explicitly permits dangerous HTML elements and attributes including <script>, <iframe>, and various JavaScript event handlers (onClick, onBlur, onChange). An unauthenticated attacker can exploit this by submitting a crafted request to inject malicious scripts into the database. These scripts are then served to and executed by any user viewing the affected content. The issue was addressed in version 9.2.3.

Affected products

  • webaways NEX-Forms – Ultimate Forms Plugin for WordPress up to, and including, 9.2.2

Timeline

  • 2026-07-01: disclosed
  • 2026-07-01: advisory

References

Related threats