Vulnerability Description
The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Basixonline | Nex-Forms | < 4.6.1 |
Related Weaknesses (CWE)
References
- http://cinu.pl/research/wp-plugins/mail_cb24b6204803e8e94943b198edc37af7.htmlExploitThird Party Advisory
- https://wordpress.org/plugins/nex-forms-express-wp-form-builder/#developersProductRelease Notes
- https://wpvulndb.com/vulnerabilities/8336ExploitThird Party Advisory
- http://cinu.pl/research/wp-plugins/mail_cb24b6204803e8e94943b198edc37af7.htmlExploitThird Party Advisory
- https://wordpress.org/plugins/nex-forms-express-wp-form-builder/#developersProductRelease Notes
- https://wpvulndb.com/vulnerabilities/8336ExploitThird Party Advisory
FAQ
What is CVE-2015-9452?
CVE-2015-9452 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id parameter.
How severe is CVE-2015-9452?
CVE-2015-9452 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-9452?
Check the references section above for vendor advisories and patch information. Affected products include: Basixonline Nex-Forms.