Impact
The NEX‑Forms plugin for WordPress contains an insufficient input validation flaw for the ‘real_val__’ parameter. Because the plugin stores the submitted value without sanitizing or escaping it, an attacker can submit arbitrary JavaScript that is then rendered to any user who views the affected form page. The vulnerability is a stored cross‑site scripting (XSS) flaw that allows unauthenticated attackers to inject web scripts that execute whenever a accesses the compromised page.
Affected Systems
The flaw is present in all releases of the webaways NEX‑Forms – Ultimate Forms Plugin for WordPress up to and including version 9.2.2. Any WordPress site that has one of these versions installed and the plugin enabled is vulnerable.
Risk and Exploitability
The CVSS score of 7.2 indicates a moderate‑to‑high severity. The EPSS score of < 1 % points to The vulnerability can be triggered remotely because the plugin registers the wp_ajax_nopriv_submit_nex_form action without nonce verification, giving unauthenticated users direct access. The flaw is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment