CVE-2026-15450
HIGH · 8.1Real vuln, high CVSS, clear exploit logic disclosed, but no PoC or KEV listing; early-stage chatter dominates.
What: Nex Forms WordPress plugin (≤9.2.3) allows authenticated admin-level attackers to delete arbitrary server files via path traversal in the delete_file() AJAX handler. CVSS 8.1 (HIGH).
Why it matters: Same-day disclosure with full NVD description detailing exploitation chain (insert_record + delete_file handlers). No KEV listing or public PoC yet, but vulnerability is straightforward and affects widely-deployed form plugin. WordPress site operators with Nex Forms should patch immediately.
Where it's seen: Initial vendor advisory and security feed republication on day of publication. Chatter limited to automated CVE aggregators and news wires; no defender triage reports or exploitation signals yet.
RISK: HIGH — Unauthenticated bypass possible if plugin user-level misconfigured; affects wp-config deletion path.
Description
The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from the database and passing it directly to unlink() with no validation (no realpath(), basename(), or allowlist check), combined with the insert_record() AJAX handler that lets the same authenticated user store an arbitrary value in the target 'location' column (wp_kses() only strips HTML tags and does not neutralize path traversal or absolute paths). This makes it possible for authenticated attackers, with admin-level access and above, to delete arbitrary files on the affected site's server, including wp-config. When the plugin's user-level option is configured to something else, this may be exploitable with lower privileges.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H- Attack vector
- Network
- Complexity
- Low
- Privileges required
- Low
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- None
- Integrity
- High
- Availability
- High
Weaknesses
References
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.3/includes/classes/class.db.php#L269
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.3/includes/classes/class.db.php#L273
- https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.3/includes/classes/class.db.php#L805
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3625615%40nex-forms-express-wp-form-builder&new=3625615%40nex-forms-express-wp-form-builder
- https://www.wordfence.com/threat-intel/vulnerabilities/id/bb5c8cb3-df67-4f2c-869a-48e34f5619ff?source=cve