SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-10525

MEDIUM · CVSS 6.1 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The NEX-Forms WordPress plugin prior to version 9.2.3 is vulnerable due to inadequate sanitization and escaping of submitted form data, resulting in a Stored Cross-Site Scripting (XSS) vulnerability. This flaw allows unauthenticated users to execute XSS attacks against high-privilege users, such as administrators, when they access the submitted entries in the admin dashboard. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-10525
Severity
MEDIUM
CVSS
6.1
EPSS
0.17%
WordPress

Original NVD Description

The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and outputting it back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users such as administrators when they view the submitted entries.