CVE-2025-69324: WordPress NEX-Forms plugin <= 9.1.7 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Stored XSS.This issue affects NEX-Forms: from n/a through <= 9.1.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69324?
CVE-2025-69324 is classified as a critical severity Cross Site Scripting (XSS) vulnerability.
How do I fix CVE-2025-69324?
To mitigate CVE-2025-69324, update the NEX-Forms plugin to version 9.1.8 or later.
What impact does CVE-2025-69324 have on users?
CVE-2025-69324 allows attackers to execute arbitrary JavaScript in the context of affected NEX-Forms installations, potentially compromising user data.
Who is affected by CVE-2025-69324?
CVE-2025-69324 affects users of the Basix NEX-Forms plugin versions 9.1.7 and earlier.
Is CVE-2025-69324 a common vulnerability?
CVE-2025-69324 is notable for its potential to be exploited across many WordPress sites using the outdated NEX-Forms plugin.