PT-2026-5500 · WordPress · Nex-Forms+1

Deadbee

·

Publicado

2026-01-31

·

Atualizado

2026-01-31

·

CVE-2025-15510

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions NEX-Forms – Ultimate Forms Plugin for WordPress versions through 9.1.8
Description The software contains a flaw that allows unauthorized access to data. A missing capability check within the NF5 Export Forms class constructor permits unauthenticated attackers to export form configurations. This export may include sensitive information such as email addresses, PayPal API credentials, and third-party integration keys. Exploitation involves enumerating the nex forms Id parameter.
Recommendations Update to a version later than 9.1.8.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-15510

Produtos afetados

Nex-Forms
Wordpress