Unrated severityNVD Advisory· Published Jul 17, 2026· Updated Jul 17, 2026
NEX-Forms < 9.2.3 - Unauthenticated Stored XSS via Form Submission
CVE-2026-10525
Description
The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and outputting it back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users such as administrators when they view the submitted entries.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/d1e191e6-ff5b-4cb8-9b12-8ae73cf0d2f0/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.