CVE-2026-9017: NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_send_nf_email AJAX Action
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the savedadminemail, saveduseremail, and saveduseremailaddress fields of arbitrary form entries belonging to other users, and cause the site to dispatch attacker-controlled email content to attacker-chosen recipient addresses.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9017?
CVE-2026-9017 is rated as medium severity with a score of 5.3.
How do I fix CVE-2026-9017?
To fix CVE-2026-9017, update the NEX-Forms plugin to a version greater than 9.2.2.
What causes CVE-2026-9017?
CVE-2026-9017 is caused by a lack of proper authorization checks in the NEX-Forms plugin.
Is CVE-2026-9017 specific to certain WordPress versions?
CVE-2026-9017 affects all versions of the NEX-Forms plugin up to and including 9.2.2 regardless of the WordPress version.
What is the impact of CVE-2026-9017?
The impact of CVE-2026-9017 allows unauthenticated users to modify form entries arbitrarily.