← Späť na vyhľadávanie CVE

CVE-2026-15450

Nex Forms

Popis

The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from the database and passing it directly to unlink() with no validation (no realpath(), basename(), or allowlist check), combined with the insert_record() AJAX handler that lets the same authenticated user store an arbitrary value in the target -location- column (wp_kses() only strips HTML tags and does not neutralize path traversal or absolute paths). This makes it possible for authenticated attackers, with admin-level access and above, to delete arbitrary files on the affected site-s server, including wp-config. When the plugin-s user-level option is configured to something else, this may be exploitable with lower privileges.

CVSS 8.1EPSS 0.376%Riziko 0.84
Zobraziť zdroj
Zverejnené
2026-08-01 09:16:59
Dotknuté verzie
<=9.2.3
Typ
Webová aplikácia
Posledná úprava
2026-08-03 20:17:13
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H