Pricing
Case studies
Login
Start trial
NEX-Forms
Basix
Developer
9.1.10
Latest version
7,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
25 patched
7 Mitigation rules
WordPress NEX-Forms - Ultimate Forms Plugin for WordPress plugin <= 9.1.9 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_id vulnerability
<= 9.1.9
17/03/2026
WordPress NEX-Forms - Ultimate Forms Plugin for WordPress plugin <= 9.1.9 - Missing Authorization to Authenticated (Subscriber+) License Deactivation via deactivate_license vulnerability
<= 9.1.9
16/03/2026
Reflected Cross Site Scripting (XSS) vulnerability
<= 9.1.7
09/02/2026
Cross Site Scripting (XSS) vulnerability
<= 9.1.7
04/02/2026
WordPress NEX-Forms - Ultimate Form Builder - Contact forms and much more plugin <= 8.5.6 - Missing Authorization via restore_records() vulnerability
<= 8.5.6
03/02/2026
WordPress NEX-Forms - Ultimate Form Builder - Contact forms and much more plugin <= 8.5.6 - Missing Authorization via set_starred() vulnerability
<= 8.5.6
03/02/2026
WordPress NEX-Forms - Ultimate Forms Plugin for WordPress plugin <= 9.1.8 - Missing Authorization to Unauthenticated Sensitive Information Exposure vulnerability
<= 9.1.8
30/01/2026
Authenticated Stored XSS vulnerability
< 9.1.8
12/01/2026
Authenticated (Admin+) SQL Injection vulnerability
<= 9.1.6
10/10/2025
Cross Site Request Forgery (CSRF) Vulnerability
<= 9.1.3
20/08/2025
Authenticated (Custom) Limited Code Execution via get_table_records Function vulnerability
<= 8.9.1
08/05/2025
Authenticated (Custom) Stored Cross-Site Scripting vulnerability
<= 8.9.1
08/05/2025
Unauthenticated Sensitive Information Exposure vulnerability
<= 8.8.1
11/03/2025
Authenticated (Admin+) SQL Injection vulnerability
<= 8.7.15
24/12/2024
SQL Injection vulnerability
<= 8.7.8
02/12/2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 8.7.3
30/09/2024
Cross Site Scripting (XSS) vulnerability
<= 8.5.10
05/07/2024
Cross Site Scripting (XSS) vulnerability
<= 8.5.5
12/02/2024
Multiple Missing Authorization vulnerability
<= 8.5.6
01/02/2024
Cross Site Request Forgery (CSRF) vulnerability
<= 8.5.2
28/12/2023
SQL Injection vulnerability
<= 8.5.5
21/12/2023
Auth. SQL Injection (SQLi) vulnerability
< 8.4
25/04/2023
Contributor+ Stored XSS vulnerability
< 8.3.3
28/03/2023
Authenticated SQL Injection (SQLi) vulnerability
<= 7.9.6
01/08/2022
Multiple Stored Cross-Site Scripting (XSS) vulnerabilities
<= 8.2
15/11/2021