Junglewise Threat Intelligence

CVE-2026-57668: Basix NEX-Forms Stored XSS in WordPress Form Builder

CVE-2026-57668 · Severity: high · CVSS 7.1 · Published 2026-07-13

Executive brief

NEX-Forms is a popular WordPress plugin used to create and manage complex web forms. A security vulnerability in this plugin allows an attacker to inject malicious scripts into the website, which could lead to unauthorized redirects, the display of fraudulent advertisements, or the theft of session information from visiting users. This could compromise the integrity of the website and the security of its visitors.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Basix NEX-Forms plugin (nex-forms-express-wp-form-builder) for WordPress due to improper neutralization of input during web page generation. The flaw allows an unauthenticated remote attacker to inject arbitrary web scripts that are permanently stored on the server. When a privileged user or a site visitor accesses the affected page, the script executes in their browser context. This can lead to session hijacking, unauthorized administrative actions, or website defacement. The vulnerability is addressed in version 9.2.3.

Affected products

  • Basix NEX-Forms - Ultimate WordPress Form Builder <= 9.2.2

Timeline

  • 2026-01-28: other: Vulnerability reported by Nguyen Ba Khanh
  • 2026-07-10: advisory: Patchstack advisory published
  • 2026-07-13: disclosed: CVE published to NVD

References