CVE-2026-12404: NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via CSVExport Class
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to enumerate sequential report IDs and download complete form submission data — including names, email addresses, phone numbers, postal addresses, payment details, and uploaded file paths — for any saved report on the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12404?
CVE-2026-12404 has a medium severity rating of 5.3.
How do I fix CVE-2026-12404?
To fix CVE-2026-12404, update the NEX-Forms Ultimate Forms Plugin for WordPress to version 9.2.3 or later.
What type of attack can exploit CVE-2026-12404?
CVE-2026-12404 can be exploited via unauthorized access to sensitive information through the CSVExport Class.
Who is affected by CVE-2026-12404?
All users of the NEX-Forms Ultimate Forms Plugin for WordPress versions up to and including 9.2.2 are affected by CVE-2026-12404.
What does CVE-2026-12404 disclose?
CVE-2026-12404 allows unauthenticated users to access sensitive information due to a lack of proper authorization checks.