What the vulnerability does
01Description
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_license() function in all versions up to, and including, 9.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to to deactivate the plugin license.
Explanation of Vulnerability in Simple Terms
02Summary
NEX-Forms versions 9.1.9 and earlier lack proper authorization checks, allowing authenticated users to modify form data they should not have access to. An attacker with a low-privilege WordPress account can alter form submissions or settings belonging to other users or forms. This affects the integrity of form data but does not expose sensitive information or take the site offline.
What an attacker can do
03Attacker Capabilities
Modify form data or settings belonging to other users or forms.
Potential impact on your site
04Site Impact
Form submissions and configurations may be altered by unauthorized users, compromising data integrity and form reliability.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress user account; no user interaction required.
Key dates
06Disclosure timeline
March 14, 2026
CVE published
April 8, 2026
Record updated