CVE-2026-9017: NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_send_nf_email AJAX Action

Published Jul 11, 2026
·
Updated

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the savedadminemail, saveduseremail, and saveduseremailaddress fields of arbitrary form entries belonging to other users, and cause the site to dispatch attacker-controlled email content to attacker-chosen recipient addresses.

Affected Software

1 affected component
NEX-Forms Ultimate Forms Plugin for WordPress<=9.2.2

Event History

Jul 11, 2026
CVE Published
via MITRE·06:50 AM
Data Sourced
via MITRE·06:50 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Jul 1, 58665
Event
via FIRST·12:28 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-9017?

CVE-2026-9017 is rated as medium severity with a score of 5.3.

2

How do I fix CVE-2026-9017?

To fix CVE-2026-9017, update the NEX-Forms plugin to a version greater than 9.2.2.

3

What causes CVE-2026-9017?

CVE-2026-9017 is caused by a lack of proper authorization checks in the NEX-Forms plugin.

4

Is CVE-2026-9017 specific to certain WordPress versions?

CVE-2026-9017 affects all versions of the NEX-Forms plugin up to and including 9.2.2 regardless of the WordPress version.

5

What is the impact of CVE-2026-9017?

The impact of CVE-2026-9017 allows unauthenticated users to modify form entries arbitrarily.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203