Executive brief
NEX-Forms is a WordPress plugin used to create and manage web forms. A security flaw allows unauthenticated attackers to inject malicious scripts into the website via form parameters. These scripts execute in the browser of any user who visits the affected page, potentially leading to unauthorized actions or data theft.
Technical details
NEX-Forms for WordPress (up to version 9.2.2) is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping of the '_name[]' array parameter. The vulnerability is exacerbated because the plugin's custom filtering function, NEXForms_allowed_tags(), explicitly permits dangerous HTML elements and attributes including <script>, <iframe>, and various JavaScript event handlers (onClick, onBlur, onChange). An unauthenticated attacker can exploit this by submitting a crafted request to inject malicious scripts into the database. These scripts are then served to and executed by any user viewing the affected content. The issue was addressed in version 9.2.3.
Affected products
- webaways NEX-Forms – Ultimate Forms Plugin for WordPress up to, and including, 9.2.2
Timeline
- 2026-07-01: disclosed
- 2026-07-01: advisory
References
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.10/includes/classes/class.db.php
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.10/includes/classes/class.db.php
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.10/includes/classes/class.functions.php
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.10/main.php
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.10/main.php
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.10/main.php
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.2/includes/classes/class.db.php