CVE-2026-10525: NEX-Forms < 9.2.3 - Unauthenticated Stored XSS via Form Submission
The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and outputting it back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users such as administrators when they view the submitted entries.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10525?
CVE-2026-10525 has a risk rating of 54, indicating a moderate severity level.
How do I fix CVE-2026-10525?
To fix CVE-2026-10525, update the NEX-Forms WordPress plugin to version 9.2.3 or later.
What type of vulnerability is CVE-2026-10525?
CVE-2026-10525 is classified as an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2026-10525?
Users of the NEX-Forms WordPress plugin prior to version 9.2.3 are affected by CVE-2026-10525.
Can CVE-2026-10525 be exploited by unauthenticated users?
Yes, CVE-2026-10525 can be exploited by unauthenticated users through form submissions.