CVE-2025-15510: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-15510 is a Missing Authorization vulnerability in the NEX-Forms – Ultimate Forms Plugin for WordPress that allows unauthenticated attackers to export sensitive form configuration data. The flaw affects all versions of the plugin up to and including 9.1.8, and stems from a missing capability check on the NF5_Export_Forms class constructor. It was published on January 31, 2026, with the CVE assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-862 (Missing Authorization): the NF5_Export_Forms class constructor in the plugin's class.export.php does not perform any capability or authentication check before processing export requests (Wordfence, WordPress Trac). An unauthenticated attacker can exploit this by enumerating the nex_forms_Id parameter in HTTP requests to trigger the export functionality and retrieve form configurations. No authentication, special privileges, or user interaction is required, and the attack is conducted entirely over the network with low complexity.

Impact

Successful exploitation allows unauthenticated remote attackers to export arbitrary form configurations from the affected WordPress site, potentially exposing sensitive data including email addresses, PayPal API credentials, and third-party integration keys stored within form settings (Wordfence). The impact is limited to confidentiality — there is no integrity or availability impact — but the exposure of API credentials and integration keys could enable further attacks against connected third-party services or facilitate account takeover scenarios.

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported as of the time of publication. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.016%, indicating a low probability of exploitation in the near term (Wordfence). However, the unauthenticated nature and the ease of parameter enumeration make it straightforward to exploit if targeted.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the NEX-Forms plugin (versions ≤ 9.1.8) using tools like WPScan, Shodan, or by checking the plugin's readme.txt file at https://target.com/wp-content/plugins/nex-forms-express-wp-form-builder/readme.txt.
  2. Identify the export endpoint: Locate the WordPress AJAX or admin endpoint that triggers the NF5_Export_Forms class constructor, typically accessible via wp-admin/admin-ajax.php or a direct plugin route without authentication.
  3. Enumerate form IDs: Send unauthenticated HTTP GET or POST requests with incrementing values of the nex_forms_Id parameter (e.g., nex_forms_Id=1, nex_forms_Id=2, etc.) to enumerate existing forms.
  4. Export form configurations: For each valid form ID, the server returns the full form configuration, which may include email addresses, PayPal API credentials, and third-party integration keys.
  5. Leverage exposed credentials: Use any harvested API keys or credentials to access connected third-party services (e.g., PayPal accounts, email marketing platforms) for further exploitation (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Repeated unauthenticated HTTP requests to WordPress AJAX endpoints (e.g., wp-admin/admin-ajax.php) with sequential or enumerated nex_forms_Id parameter values from a single or rotating IP address.
  • Logs: Web server access logs showing a high volume of requests to the NEX-Forms export endpoint without corresponding authenticated sessions; HTTP 200 responses to unauthenticated export requests.
  • File System: No direct file system artifacts expected, as this is a data exfiltration vulnerability with no file write capability.

Mitigation and workarounds

Users should update the NEX-Forms – Ultimate Forms Plugin for WordPress to version 9.1.9 or later, which is expected to include the missing authorization check on the export functionality (Wordfence). As an interim workaround, site administrators can deactivate the plugin until a patched version is applied, or use a Web Application Firewall (WAF) rule to block unauthenticated access to the export endpoint. Additionally, administrators should audit any API credentials or sensitive data stored in form configurations and rotate them if exposure is suspected.

Community reactions

Wordfence reported this vulnerability as part of their weekly WordPress vulnerability report covering January 26–February 1, 2026, noting the missing capability check as the core issue (Wordfence Blog). No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been identified.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management