The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This vulnerability allows authenticated attackers with admin-level access and above to delete arbitrary files on the affected site's server, including wp-config, due to insufficient validation in the delete_file() AJAX handler and the insert [truncated]
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin is vulnerable to authorization bypass. This allows unauthenticated attackers to modify form entries and dispatch malicious emails. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. The plugin fails to properly verify user authorization for certain actions, allowing attackers to overwrite saved email fields of arbitrar [truncated]
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. [truncated]
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin, up to and including version 9.2.2, is vulnerable to authorization bypass. This vulnerability allows unauthenticated attackers to enumerate sequential report IDs and download complete form submission data, including sensitive information such as names, email addresses, phone numbers, postal addresses, payment details, and uploaded file paths, for [truncated]