CVE-2025-49399: WordPress NEX-Forms Plugin <= 9.1.3 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms allows Cross Site Request Forgery. This issue affects NEX-Forms: from n/a through 9.1.3.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Cross Site Request Forgery.This issue affects NEX-Forms: from n/a through <= 9.1.3.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49399?
CVE-2025-49399 is classified as a critical Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2025-49399?
To fix CVE-2025-49399, update the NEX-Forms plugin to the latest version beyond 9.1.3.
What versions of NEX-Forms are affected by CVE-2025-49399?
CVE-2025-49399 affects all versions of NEX-Forms from its initial release up to version 9.1.3.
What impact does CVE-2025-49399 have on users?
CVE-2025-49399 can allow an attacker to execute unauthorized actions on behalf of users without their consent.
Is CVE-2025-49399 a common vulnerability in web applications?
Yes, Cross-Site Request Forgery (CSRF) vulnerabilities like CVE-2025-49399 are common in web applications and can pose significant security risks.