PT-2025-41642 · WordPress · Nex-Forms – Ultimate Forms Plugin For Wordpress

Đức Tài

+1

·

Published

2025-10-11

·

Updated

2025-10-11

·

CVE-2025-10185

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions NEX-Forms – Ultimate Forms Plugin for WordPress versions through 9.1.6
Description The software is susceptible to SQL Injection through the orderby parameter within the nf load form entries action. Insufficient input sanitization and inadequate SQL query preparation allow authenticated attackers with Administrator-level access or higher to inject additional SQL queries, potentially extracting sensitive database information. Lower-level users may also be able to exploit this if granted access by a site administrator.
Recommendations Update NEX-Forms – Ultimate Forms Plugin for WordPress to a version later than 9.1.6.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-10185

Affected Products

Nex-Forms – Ultimate Forms Plugin For Wordpress