PT-2026-55495 · WordPress · Nex-Forms

·

CVE-2026-13040

·

Published

2026-07-03

·

Updated

2026-07-07

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions NEX-Forms – Ultimate Forms Plugin for WordPress versions prior to 9.2.3
Description Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS), a technique where malicious scripts are permanently stored on the target server. Attackers can inject arbitrary web scripts via the real val parameter, which execute when a user accesses the affected page. The submission endpoint wp ajax nopriv submit nex form lacks nonce verification, allowing access without a Cross-Site Request Forgery (CSRF) token.
Recommendations Update to a version newer than 9.2.2. Avoid using the real val parameter in the wp ajax nopriv submit nex form endpoint until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13040

Affected Products

Nex-Forms