Description
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up to, and including, 9.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The operator allowlist applied by get_table_records() when building its own WHERE fragment is not enforced on the same tainted additional_params array when it is forwarded to get_total_records(), leaving the SQL sink unprotected.
Published: 2026-09-18
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

NEX-Forms – Ultimate Forms Plugin for WordPress is susceptible to a generic SQL Injection that originates from the unescaped 'additional_params' parameter. The vulnerability arises when the operator allowlist applied by get_table_records() is omitted while passing the same array to get_total_records(), creating an unprotected SQL sink. The flaw enables authenticated administrators or users with elevated privileges to inject arbitrary SQL fragments that can read or exfiltrate sensitive database information, potentially exposing user data, credentials, or other confidential content. However, the exploit does not provide remote code execution, denial of service, or privilege escalation beyond the existing authenticated user level.

Affected Systems

All installations of NEX-Forms – Ultimate Forms Plugin for WordPress provided by webaways that run version 9.3.0 or earlier are affected. This includes every WordPress site deploying the plugin up to and including the 9.3.0 release.

Risk and Exploitability

The CVSS score of 4.9 indicates a medium impact level, and the EPSS score of less than 1% reflects a low probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires an authenticated attacker with at least administrator privileges who can craft requests containing a malicious 'operator' key within the 'additional_params' array. The attack vector is confined to web requests processed by the plugin, and the impact is limited to unauthorized disclosure of database content rather than execution of arbitrary code.

Generated by OpenCVE AI on September 19, 2026 at 20:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade NEX-Forms to the latest available version (9.4 or later) which eliminates the SQL injection flaw.
  • If an immediate upgrade is not possible, disable or remove the 'additional_params' functionality for all non‑essential user roles via plugin settings or custom capability adjustments.
  • Enforce stricter role‑based access control so that only a small set of trusted administrators can trigger the plugin’s advanced features.
  • Review the plugin’s source or configuration to ensure that all inputs, especially 'additional_params', are handled with prepared statements or appropriate escaping before inclusion in SQL queries.

Generated by OpenCVE AI on September 19, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Webaways
Webaways nex-forms-ultimate-forms-plugin
Wordpress
Wordpress wordpress
Vendors & Products Webaways
Webaways nex-forms-ultimate-forms-plugin
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up to, and including, 9.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The operator allowlist applied by get_table_records() when building its own WHERE fragment is not enforced on the same tainted additional_params array when it is forwarded to get_total_records(), leaving the SQL sink unprotected.
Title NEX-Forms <= 9.3.0 - Authenticated (Administrator+) SQL Injection via 'operator' Key of the 'additional_params' Parameter
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Webaways Nex-forms-ultimate-forms-plugin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:21:52.014Z

Reserved: 2026-08-18T16:34:46.143Z

Link: CVE-2026-75961

cve-icon Vulnrichment

Updated: 2026-09-19T14:14:07.043Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T08:17:01.227

Modified: 2026-09-19T15:17:00.990

Link: CVE-2026-75961

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:30:25Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')