CVE-2026-96607: WordPress NEX-Forms plugin <= 9.3.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Reflected XSS.This issue affects NEX-Forms: from n/a through 9.3.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Basix NEX-Forms nex-forms-express-wp-form-builderto a version that resolves this vulnerability.Fixed in 9.3.2
Event History
Frequently Asked Questions
Which installations are affected?
Installations using the Basix NEX-Forms plugin are affected through version 9.3.1. The available information does not identify an unaffected fixed version.
What does exploitation require?
The vulnerability is reachable over the network and does not require attacker privileges. Exploitation requires user interaction, meaning a victim must interact with attacker-supplied content or a crafted request.