Authorization Bypass Vulnerability in NEX-Forms Plugin for WordPress
CVE-2026-12404
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 June 2026
What is CVE-2026-12404?
The NEX-Forms β Ultimate Forms Plugin for WordPress is susceptible to an authorization bypass vulnerability in all versions up to 9.2.2. This flaw arises from the plugin's failure to adequately verify user permissions, allowing unauthenticated attackers to access and enumerate report IDs, potentially downloading complete form submission data. This includes sensitive information such as names, email addresses, phone numbers, postal addresses, payment details, and file paths associated with uploaded content, posing significant privacy risks to users.
Affected Version(s)
NEX-Forms β Ultimate Forms Plugin for WordPress 0 <= 9.2.2