Impact
The NEX‑Forms WordPress plugin before version 9.2.3 stores certain form field values without proper sanitization or escaping and later outputs those values directly in the admin dashboard. This flaw allows an attacker to inject arbitrary JavaScript code that will execute with the privileges of any administrator who views the stored form entry. No additional information about data exfiltration or system compromise is provided, but the injected code could be used to hijack sessions, steal credentials, or modify site content.
Affected Systems
The vulnerability is present on any WordPress site that has the NEX‑Forms plugin installed with a version older than 9.2.3. No specific operating system or server platform constraints are mentioned, and the vendor beyond the plugin name is currently unknown.
Risk and Exploitability
A CVSS score of 6.1 indicates moderate severity, and an EPSS score of less than 1 percent reflects a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker does not need admin credentials; it is sufficient to submit malicious input through any publicly accessible form powered by NEX‑Forms before version 9.2.3. The payload is stored in the database and will execute with administrator privileges when an admin later views the stored entry in the back‑end.
OpenCVE Enrichment