NEX-Forms Ultimate Form Builder
cpe:2.3:a:nex-forms_-_ultimate_form_builder_project:nex-forms_-_ultimate_form_builder:*:*:*:*:wordpress:*:*
- <= 8.9.1
A limited code execution vulnerability has been identified in the NEX-Forms – Ultimate Form Builder – Contact Forms and Much More plugin for WordPress, affecting all versions through 8.9.1. The vulnerability arises from the get_table_records function, where user-supplied input is improperly sanitized before being used in call_user_func(). This flaw allows authenticated attackers with Custom-level access to execute arbitrary PHP functions, provided they are static methods or global functions that accept a single array parameter.
Exploitation of this vulnerability could lead to unauthorized execution of PHP code on the server, potentially allowing attackers to execute malicious functions or manipulate the site in harmful ways.
Users are advised to update the NEX-Forms WordPress plugin to version 8.9.2 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.