CVE-2025-14803: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14803 is an Authenticated Stored Cross-Site Scripting (XSS) vulnerability in the NEX-Forms – Express WP Form Builder WordPress plugin affecting all versions before 9.1.8. The flaw arises because the plugin fails to sanitize and escape certain settings, and can be configured to allow subscriber-level users to inject and store malicious scripts. It was publicly disclosed on December 19, 2025, and assigned a CVSS v3.1 base score of 6.8 (Medium) (WPScan, Feedly).

Technical details

The root cause is improper neutralization of user-supplied input during web page generation (CWE-79). When an administrator enables form creation access for subscriber-level users via the plugin's global settings, those users can navigate to the form editor, add a Hidden Field under "Extra Field Options," and inject a malicious payload such as '"<img src=x onerror=alert(1)> into the field values. Because the plugin stores these values without adequate sanitization or output escaping, the payload is persisted in the database and executed in the browser of any privileged user (e.g., an admin) who subsequently views the form. The attack vector is network-based, requires high privileges by default (but can be delegated to subscribers), and requires user interaction to trigger (WPScan).

Impact

Successful exploitation allows an attacker with form-creation access (subscriber or higher, depending on plugin configuration) to store malicious JavaScript that executes in the context of any administrator or privileged user who views the affected form. This can lead to session hijacking, credential theft, unauthorized administrative actions (such as creating rogue admin accounts or installing malicious plugins), and potential full site compromise. The confidentiality, integrity, and availability impacts are all rated High under the CVSS scoring (WPScan, Feedly).

Exploitability

A verified proof-of-concept (PoC) is publicly available via WPScan, demonstrating the full exploitation path. The EPSS score is approximately 0.029% (0.000290), indicating a low but non-zero probability of exploitation in the wild. No evidence of active in-the-wild exploitation, exploit kit integration, or threat actor attribution has been reported at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (WPScan, Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the NEX-Forms – Express WP Form Builder plugin at a version below 9.1.8 using tools like WPScan or by inspecting plugin metadata in page source.
  2. Obtain subscriber access: Register or log in as a subscriber-level user on the target WordPress site.
  3. Check for delegated form creation: Verify that the site administrator has enabled form creation access for subscribers via https://example.com/wp-admin/admin.php?page=nex-forms-page-global-settings. If not enabled, this step is a prerequisite that limits exploitability.
  4. Create a malicious form: Navigate to https://example.com/wp-admin/admin.php?page=nex-forms-dashboard and create a new blank form with any name.
  5. Inject XSS payload: In the form editing screen, go to "Extra Field Options" and click "Add Hidden Field". Enter the payload '"<img src=x onerror=alert(1)> (or a more malicious script, e.g., a cookie-stealing payload) into both the field name and value fields.
  6. Save the form: Submit and save the form, persisting the payload in the database.
  7. Trigger execution: When an administrator views or previews the form in the WordPress admin panel, the stored payload executes in their browser context, enabling session token theft, unauthorized actions, or further compromise (WPScan).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to /wp-admin/admin.php?page=nex-forms-dashboard from subscriber-level accounts, particularly containing encoded HTML or JavaScript in form field parameters.
  • Database: Unexpected or obfuscated HTML/JavaScript content (e.g., <script>, <img src=x onerror=, onerror=, javascript:) stored in the NEX-Forms plugin database tables (typically prefixed with wp_nex_forms_*).
  • Browser/Admin Panel: Unexpected JavaScript alerts, redirects, or network requests originating from the WordPress admin panel when viewing NEX-Forms form entries.
  • Network: Outbound HTTP requests from an administrator's browser session to unknown external domains shortly after viewing a NEX-Forms form, potentially indicating cookie exfiltration (WPScan).

Mitigation and workarounds

Update the NEX-Forms – Express WP Form Builder plugin to version 9.1.8 or later, which includes the fix for this vulnerability. As an interim workaround, administrators should revoke form creation access from subscriber-level users via the plugin's global settings page (/wp-admin/admin.php?page=nex-forms-page-global-settings), limiting form creation to trusted roles only. Regularly audit plugin settings and user role permissions to minimize the attack surface (WPScan).

Community reactions

The vulnerability was discovered and responsibly disclosed by the Vuln Seeker Cyber Security Team, who submitted it to WPScan. No significant vendor statements beyond the patch release, notable researcher commentary, or broad media coverage have been identified for this vulnerability (WPScan).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management