
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14803 is an Authenticated Stored Cross-Site Scripting (XSS) vulnerability in the NEX-Forms – Express WP Form Builder WordPress plugin affecting all versions before 9.1.8. The flaw arises because the plugin fails to sanitize and escape certain settings, and can be configured to allow subscriber-level users to inject and store malicious scripts. It was publicly disclosed on December 19, 2025, and assigned a CVSS v3.1 base score of 6.8 (Medium) (WPScan, Feedly).
The root cause is improper neutralization of user-supplied input during web page generation (CWE-79). When an administrator enables form creation access for subscriber-level users via the plugin's global settings, those users can navigate to the form editor, add a Hidden Field under "Extra Field Options," and inject a malicious payload such as '"<img src=x onerror=alert(1)> into the field values. Because the plugin stores these values without adequate sanitization or output escaping, the payload is persisted in the database and executed in the browser of any privileged user (e.g., an admin) who subsequently views the form. The attack vector is network-based, requires high privileges by default (but can be delegated to subscribers), and requires user interaction to trigger (WPScan).
Successful exploitation allows an attacker with form-creation access (subscriber or higher, depending on plugin configuration) to store malicious JavaScript that executes in the context of any administrator or privileged user who views the affected form. This can lead to session hijacking, credential theft, unauthorized administrative actions (such as creating rogue admin accounts or installing malicious plugins), and potential full site compromise. The confidentiality, integrity, and availability impacts are all rated High under the CVSS scoring (WPScan, Feedly).
A verified proof-of-concept (PoC) is publicly available via WPScan, demonstrating the full exploitation path. The EPSS score is approximately 0.029% (0.000290), indicating a low but non-zero probability of exploitation in the wild. No evidence of active in-the-wild exploitation, exploit kit integration, or threat actor attribution has been reported at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (WPScan, Feedly).
https://example.com/wp-admin/admin.php?page=nex-forms-page-global-settings. If not enabled, this step is a prerequisite that limits exploitability.https://example.com/wp-admin/admin.php?page=nex-forms-dashboard and create a new blank form with any name.'"<img src=x onerror=alert(1)> (or a more malicious script, e.g., a cookie-stealing payload) into both the field name and value fields./wp-admin/admin.php?page=nex-forms-dashboard from subscriber-level accounts, particularly containing encoded HTML or JavaScript in form field parameters.<script>, <img src=x onerror=, onerror=, javascript:) stored in the NEX-Forms plugin database tables (typically prefixed with wp_nex_forms_*).Update the NEX-Forms – Express WP Form Builder plugin to version 9.1.8 or later, which includes the fix for this vulnerability. As an interim workaround, administrators should revoke form creation access from subscriber-level users via the plugin's global settings page (/wp-admin/admin.php?page=nex-forms-page-global-settings), limiting form creation to trusted roles only. Regularly audit plugin settings and user role permissions to minimize the attack surface (WPScan).
The vulnerability was discovered and responsibly disclosed by the Vuln Seeker Cyber Security Team, who submitted it to WPScan. No significant vendor statements beyond the patch release, notable researcher commentary, or broad media coverage have been identified for this vulnerability (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."