Descrição
The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from the database and passing it directly to unlink() with no validation (no realpath(), basename(), or allowlist check), combined with the insert_record() AJAX handler that lets the same authenticated user store an arbitrary value in the target -location- column (wp_kses() only strips HTML tags and does not neutralize path traversal or absolute paths). This makes it possible for authenticated attackers, with admin-level access and above, to delete arbitrary files on the affected site-s server, including wp-config. When the plugin-s user-level option is configured to something else, this may be exploitable with lower privileges.
- Publicação
- 2026-08-01 09:16:59
- Versões afetadas
- <=9.2.3
- Tipo
- Aplicação web
- Última alteração
- 2026-08-03 20:17:13
- Vetor
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H