The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the clean_html and form_fields parameters in all versions up to, and including, 8.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Jun 2025 23:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Basixonline
Basixonline nex-forms |
|
CPEs | cpe:2.3:a:basixonline:nex-forms:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Basixonline
Basixonline nex-forms |
Thu, 08 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 08 May 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the clean_html and form_fields parameters in all versions up to, and including, 8.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
Title | NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) Stored Cross-Site Scripting | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-05-08T11:13:44.979Z
Updated: 2025-05-08T13:34:14.166Z
Reserved: 2025-04-09T11:54:37.522Z
Link: CVE-2025-3468

Updated: 2025-05-08T13:33:27.396Z

Status : Analyzed
Published: 2025-05-08T12:15:17.643
Modified: 2025-06-04T22:54:54.960
Link: CVE-2025-3468

No data.