NEX-Forms – Ultimate Form Builder – Contact forms and much more, 1ef9880c1ec26687ed87e181f557ff2b031ed65b
- CVE, Research URL
- Home page URL
-
Security reports for NEX-Forms – Ultimate Form Builder – Contact forms and much more
- Published on
- -
- Research Description
- NEX-Forms – Ultimate Forms Plugin for WordPress [nex-forms-express-wp-form-builder] < 8.5.7 WordPress NEX-Forms – Ultimate Form Builder Plugin <= 8.5.6 is vulnerable to Broken Access Control Update the WordPress NEX-Forms – Ultimate Form Builder plugin to the latest available version (at least 8.5.7). Francesco Carlucci discovered and reported this Broken Access Control vulnerability in WordPress NEX-Forms – Ultimate Form Builder Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 8.5.7. Have additional information or questions about this entry? Get in touch.
- Affected versions
-
max 8.5.7.
- Status
-
vulnerable