Executive brief
The NEX-Forms plugin for WordPress, which is used to create and manage website forms, contains a security flaw that allows unauthorized access to submitted data. An attacker can exploit this to download sensitive information provided by users, such as names, email addresses, phone numbers, and payment details. This could lead to significant privacy breaches and the exposure of customer personal information.
Technical details
The NEX-Forms plugin for WordPress (versions up to 9.2.2) fails to implement proper authorization checks on its reporting functionality. This missing authorization (CWE-862) allows unauthenticated remote attackers to perform ID enumeration on sequential report IDs. By iterating through these IDs, an attacker can download full form submission records, which include PII such as names, emails, addresses, and payment details, as well as paths to uploaded files. The vulnerability is exploitable via direct network requests without any prior authentication or user interaction.
Affected products
- webaways NEX-Forms – Ultimate Forms Plugin for WordPress up to and including 9.2.2
Timeline
- 2026-06-27: disclosed
- 2026-06-27: advisory
References
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.12/main.php
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.12/main.php
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.12/main.php
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.2/main.php
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.2/main.php
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.2/main.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3584399%40nex-forms-express-wp-form-builder&new=3584399%40nex-forms-express-wp-form-builder&sfp_email=&sfph_mail=