SQL Injection Vulnerability in NEX-Forms Plugin for WordPress
CVE-2026-75961
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 September 2026
What is CVE-2026-75961?
The NEX-Forms β Ultimate Forms Plugin for WordPress is susceptible to an SQL injection flaw due to improper escaping of user inputs in the 'additional_params' parameter. This vulnerability exists across all versions leading up to and including version 9.3.0. Authenticated attackers with custom-level access can manipulate SQL queries by injecting additional commands, risking the exposure of sensitive information from the database. The inadequately enforced allowlist when processing the additional_params compromises the security of the SQL queries executed, leading to potential data breaches.
Affected Version(s)
NEX-Forms β Ultimate Forms Plugin for WordPress 0 <= 9.3.0