PatchSiren

webaways CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH webaways CVE published 2026-08-01

CVE-2026-15450

The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This vulnerability allows authenticated attackers with admin-level access and above to delete arbitrary files on the affected site's server, including wp-config, due to insufficient validation in the delete_file() AJAX handler and the insert [truncated]

MEDIUM webaways CVE published 2026-07-11

CVE-2026-9017

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin is vulnerable to authorization bypass. This allows unauthenticated attackers to modify form entries and dispatch malicious emails. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. The plugin fails to properly verify user authorization for certain actions, allowing attackers to overwrite saved email fields of arbitrar [truncated]

HIGH webaways CVE published 2026-07-03

CVE-2026-13040

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. [truncated]

MEDIUM webaways CVE published 2026-06-27

CVE-2026-12404

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin, up to and including version 9.2.2, is vulnerable to authorization bypass. This vulnerability allows unauthenticated attackers to enumerate sequential report IDs and download complete form submission data, including sensitive information such as names, email addresses, phone numbers, postal addresses, payment details, and uploaded file paths, for [truncated]