Junglewise Threat Intelligence

CVE-2026-13040: Webaways NEX-Forms Stored XSS in real_val__ parameter

CVE-2026-13040 · Severity: high · CVSS 7.2 · Published 2026-07-03

Technologies: Webaways NEX-Forms – Ultimate Forms Plugin for WordPress. Vendors: Webaways.

Executive brief

NEX-Forms, a popular form-building plugin for WordPress, contains a security flaw that allows unauthorized individuals to inject malicious scripts into website pages. This occurs because the plugin does not properly check information submitted through its forms. If exploited, an attacker could steal user session data or redirect visitors to malicious websites whenever they view the affected pages.

Technical details

The NEX-Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'real_val__' parameter. The vulnerability is accessible via the 'wp_ajax_nopriv_submit_nex_form' AJAX action, which lacks nonce verification, allowing unauthenticated attackers to submit malicious payloads without a CSRF token. When these payloads are later viewed by other users (such as administrators reviewing form submissions), the injected scripts execute. This affects all versions up to and including 9.2.2.

Affected products

  • webaways NEX-Forms – Ultimate Forms Plugin for WordPress up to, and including, 9.2.2

Timeline

  • 2026-07-03: advisory: NVD publication date

References

Related threats