Executive brief
NEX-Forms is a popular WordPress plugin used to build and manage website forms. A security flaw allows unauthorized individuals to modify email settings within existing form entries. This could allow an attacker to redirect form notifications to their own email addresses or send unauthorized content through the website's email system, potentially damaging the site's reputation or intercepting sensitive user communications.
Technical details
The NEX-Forms plugin for WordPress (versions up to 9.2.2) suffers from a missing authorization check (CWE-862). This vulnerability allows unauthenticated remote attackers to overwrite the 'saved_admin_email', 'saved_user_email', and 'saved_user_email_address' fields of arbitrary form entries. By manipulating these fields, an attacker can cause the site to dispatch attacker-controlled email content to arbitrary recipient addresses. The issue stems from the plugin failing to verify if a user has the necessary permissions to perform these specific update actions.
Affected products
- webaways NEX-Forms – Ultimate Forms Plugin for WordPress up to, and including, 9.2.2
Timeline
- 2026-07-11: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.10/main.php
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.10/main.php
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.10/main.php
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.13/main.php
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.13/main.php
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.13/main.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3584399%40nex-forms-express-wp-form-builder&new=3584399%40nex-forms-express-wp-form-builder