SQL Injection Vulnerability in Nex-Forms Express WP Form Builder by WordPress
CVE-2015-9452
9.8CRITICAL
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 7 October 2019
What is CVE-2015-9452?
A vulnerability exists in the Nex-Forms Express WP Form Builder plugin prior to version 4.6.1, allowing attackers to perform SQL injection attacks via the nex_forms_Id
parameter in the wp-admin/admin.php?page=nex-forms-main
endpoint. This flaw can potentially enable unauthorized access to sensitive information or facilitate further exploitation of the affected system. Website owners using this plugin are advised to update to the latest version to mitigate these risks.