The NEX-Forms – Ultimate Forms Plugin for WordPress is...
Moderate severity
Unreviewed
Published
Jan 31, 2026
to the GitHub Advisory Database
•
Updated Jan 31, 2026
Description
Published by the National Vulnerability Database
Jan 31, 2026
Published to the GitHub Advisory Database
Jan 31, 2026
Last updated
Jan 31, 2026
The NEX-Forms – Ultimate Forms Plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the NF5_Export_Forms class constructor in all versions up to, and including, 9.1.8. This makes it possible for unauthenticated attackers to export form configurations, that may include sensitive data, such as email addresses, PayPal API credentials, and third-party integration keys by enumerating the nex_forms_Id parameter.
References