CVE-2026-57668: WordPress NEX-Forms plugin <= 9.2.2 - Cross Site Scripting (XSS) vulnerability
Published Jul 13, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Stored XSS.This issue affects NEX-Forms: from n/a through <= 9.2.2.
Affected Software
2 affected components
Basix NEX-Forms nex-forms-express-wp-form-builder<=9.2.2
WordPress NEX-Forms<=9.2.2
Event History
Jul 13, 2026
CVE Published
via MITRE·08:41 AM
Data Sourced
via MITRE·08:41 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-57668?
CVE-2026-57668 has a high severity rating of 7.1.
2
How do I fix CVE-2026-57668?
To fix CVE-2026-57668, update the NEX-Forms plugin to a version later than 9.2.2.
3
What type of vulnerability is CVE-2026-57668?
CVE-2026-57668 is a Cross-Site Scripting (XSS) vulnerability.
4
What software is affected by CVE-2026-57668?
CVE-2026-57668 affects the Basix NEX-Forms plugin versions up to and including 9.2.2.
5
What impact does CVE-2026-57668 have on users?
CVE-2026-57668 allows for Stored XSS, which can compromise user data and exploit web sessions.