
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15510 is a Missing Authorization vulnerability in the NEX-Forms – Ultimate Forms Plugin for WordPress that allows unauthenticated attackers to export sensitive form configuration data. The flaw affects all versions of the plugin up to and including 9.1.8, and stems from a missing capability check on the NF5_Export_Forms class constructor. It was published on January 31, 2026, with the CVE assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-862 (Missing Authorization): the NF5_Export_Forms class constructor in the plugin's class.export.php does not perform any capability or authentication check before processing export requests (Wordfence, WordPress Trac). An unauthenticated attacker can exploit this by enumerating the nex_forms_Id parameter in HTTP requests to trigger the export functionality and retrieve form configurations. No authentication, special privileges, or user interaction is required, and the attack is conducted entirely over the network with low complexity.
Successful exploitation allows unauthenticated remote attackers to export arbitrary form configurations from the affected WordPress site, potentially exposing sensitive data including email addresses, PayPal API credentials, and third-party integration keys stored within form settings (Wordfence). The impact is limited to confidentiality — there is no integrity or availability impact — but the exposure of API credentials and integration keys could enable further attacks against connected third-party services or facilitate account takeover scenarios.
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported as of the time of publication. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.016%, indicating a low probability of exploitation in the near term (Wordfence). However, the unauthenticated nature and the ease of parameter enumeration make it straightforward to exploit if targeted.
https://target.com/wp-content/plugins/nex-forms-express-wp-form-builder/readme.txt.NF5_Export_Forms class constructor, typically accessible via wp-admin/admin-ajax.php or a direct plugin route without authentication.nex_forms_Id parameter (e.g., nex_forms_Id=1, nex_forms_Id=2, etc.) to enumerate existing forms.wp-admin/admin-ajax.php) with sequential or enumerated nex_forms_Id parameter values from a single or rotating IP address.Users should update the NEX-Forms – Ultimate Forms Plugin for WordPress to version 9.1.9 or later, which is expected to include the missing authorization check on the export functionality (Wordfence). As an interim workaround, site administrators can deactivate the plugin until a patched version is applied, or use a Web Application Firewall (WAF) rule to block unauthenticated access to the export endpoint. Additionally, administrators should audit any API credentials or sensitive data stored in form configurations and rotate them if exposure is suspected.
Wordfence reported this vulnerability as part of their weekly WordPress vulnerability report covering January 26–February 1, 2026, noting the missing capability check as the core issue (Wordfence Blog). No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."