SQL Injection Vulnerability in NEX-Forms Plugin for WordPress
CVE-2026-15602
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 August 2026
What is CVE-2026-15602?
The NEX-Forms β Ultimate Forms Plugin for WordPress has a vulnerability that allows authenticated users with admin-level access to exploit SQL Injection via the 'additional_params' parameter. This flaw arises from inadequate escaping of user-supplied data and insufficient preparation of existing SQL queries. Attackers can inject additional SQL commands, leading to potential extraction of sensitive database information. The vulnerability is categorized as a second-order SQL injection, where the payload is stored through the submission_report2 AJAX handler, which lacks necessary nonce checks, allowing its execution during CSV export processes.
Affected Version(s)
NEX-Forms β Ultimate Forms Plugin for WordPress 0 <= 9.2.4