Impact
NEX-Forms – Ultimate Forms Plugin for WordPress is susceptible to a generic SQL Injection that originates from the unescaped 'additional_params' parameter. The vulnerability arises when the operator allowlist applied by get_table_records() is omitted while passing the same array to get_total_records(), creating an unprotected SQL sink. The flaw enables authenticated administrators or users with elevated privileges to inject arbitrary SQL fragments that can read or exfiltrate sensitive database information, potentially exposing user data, credentials, or other confidential content. However, the exploit does not provide remote code execution, denial of service, or privilege escalation beyond the existing authenticated user level.
Affected Systems
All installations of NEX-Forms – Ultimate Forms Plugin for WordPress provided by webaways that run version 9.3.0 or earlier are affected. This includes every WordPress site deploying the plugin up to and including the 9.3.0 release.
Risk and Exploitability
The CVSS score of 4.9 indicates a medium impact level, and the EPSS score of less than 1% reflects a low probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires an authenticated attacker with at least administrator privileges who can craft requests containing a malicious 'operator' key within the 'additional_params' array. The attack vector is confined to web requests processed by the plugin, and the impact is limited to unauthorized disclosure of database content rather than execution of arbitrary code.
OpenCVE Enrichment