Impact
The vulnerable plugin allows attackers with administrative or higher privileges to inject arbitrary SQL through the "additional_params" field. Because the plugin does not escape this parameter or use prepared statements, malicious input is stored via the submission_report2 AJAX handler and later executed when a CSV export is generated. This second‑order defect can be used to read sensitive database information, compromising confidentiality and integrity of the site.
Affected Systems
Webaways NEX‑Forms – Ultimate Forms Plugin for WordPress, all releases up to and including version 9.2.4 are affected. Sites running WordPress with these plugin versions are at risk.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, but the vulnerability can be exploited only by authenticated users with admin‑level access or any capability configured for the AJAX handler. No exploit database listing or KEV flag exists, and the EPSS score is not available, so public exploitation is currently unlikely. Nonetheless, the possibility of credential compromise or privilege escalation makes the vulnerability a notable threat to data confidentiality.
OpenCVE Enrichment