CVE-2025-15510: NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.8 - Missing Authorization to Unauthenticated Sensitive Information Exposure
The NEX-Forms – Ultimate Forms Plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the NF5ExportForms class constructor in all versions up to, and including, 9.1.8. This makes it possible for unauthenticated attackers to export form configurations, that may include sensitive data, such as email addresses, PayPal API credentials, and third-party integration keys by enumerating the nexformsId parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15510?
CVE-2025-15510 is classified as a high-severity vulnerability due to its potential for unauthorized sensitive information exposure.
What versions are affected by CVE-2025-15510?
CVE-2025-15510 affects NEX-Forms – Ultimate Forms Plugin for WordPress versions up to and including 9.1.8.
How do I fix CVE-2025-15510?
To fix CVE-2025-15510, update the NEX-Forms – Ultimate Forms Plugin to the latest version that addresses the missing authorization issue.
What type of vulnerability is CVE-2025-15510?
CVE-2025-15510 is an unauthorized access vulnerability that allows unauthenticated users to expose sensitive information.
Is there a workaround for CVE-2025-15510?
Currently, there is no specific workaround available for CVE-2025-15510 aside from updating the plugin.