NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.12 - Authenticated (Administrator+) SQL Injection via 'table' Parameter
NEX-Forms – Ultimate Forms Plugin for WordPress
Minimum safe version
9.1.13
Update to 9.1.13 or later to address 38 fixable vulnerabilities
CVE-2026-5063
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Authenticated (Subscriber+) License Deactivation via deactivate_license
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_id
CVE-2025-69326
CVE-2025-69324
CVE-2025-15510
CVE-2025-14803
CVE-2025-10185
CVE-2025-49399
NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) Stored Cross-Site Scripting
NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) Limited Code Execution via get_table_records Function
CVE-2024-13498
CVE-2024-10862
CVE-2024-53808
CVE-2024-47389
CVE-2024-37512
CVE-2024-25593
CVE-2024-1129
CVE-2024-1130
WordPress NEX-Forms – Ultimate Form Builder Plugin <= 8.5.6 is vulnerable to Broken Access Control
NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via set_read()
NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via set_starred()
CVE-2024-0907
WordPress NEX-Forms – Ultimate Form Builder Plugin <= 8.5.2 is vulnerable to Cross Site Request Forgery (CSRF)
WordPress NEX-Forms – Ultimate Form Builder Plugin <= 8.5.5 is vulnerable to SQL Injection
NEX-Forms - Ultimate Form builder <= 3.0 - SQL Injection
CVE-2023-0439
CVE-2023-2114
WordPress NEX-Forms – Ultimate Form Builder Plugin < 8.3.3 is vulnerable to Cross Site Scripting (XSS)
NEX-Forms – Ultimate Form Builder – Contact forms and much more < 3.4 - SQL Injection
CVE-2021-34676
CVE-2022-3142
WordPress NEX-Forms <= 2.9 - SQL Injection
WordPress NEX-Forms Plugin <= 4.0 - Blind SQL Injection
CVE-2014-7151
CVE-2015-9452
CVE-2021-24705