What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms – Ultimate Form Builder – Contact forms and much more.This issue affects NEX-Forms – Ultimate Form Builder – Contact forms and much more: from n/a through 8.5.2.
Explanation of Vulnerability in Simple Terms
02Summary
NEX-Forms versions up to 8.5.2 are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions within the form builder without their knowledge. The vulnerability requires user interaction—the admin must visit the attacker's page—but can modify form settings or data once triggered.
What an attacker can do
03Attacker Capabilities
Trick a logged-in admin into modifying form settings or data by visiting a malicious webpage.
Potential impact on your site
04Site Impact
An attacker can alter your forms' configuration, fields, or submissions without your consent if an admin visits a malicious link.
Conditions required to exploit
05Prerequisites
Admin must be logged in and visit an attacker-controlled page; no special privileges or authentication by attacker needed.
Key dates
06Disclosure timeline
January 5, 2024
CVE published
April 28, 2026
Record updated