CVE-2020-36670
NEX-Forms <= 7.7.1 - Missing Authorization on Various AJAX Actions
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th
The NEX-Forms. plugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versions up to, and including 7.7.1 due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber level permissions and above to invoke these functions which can be used to perform actions like modify form submission records, deleting files, sending test emails, modifying plugin settings, and more.
| CWE | CWE-862 |
| Vendor | webaways |
| Product | nex-forms – ultimate forms plugin for wordpress |
| Published | Mar 7, 2023 |
| Last Updated | Apr 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for webaways nex-forms – ultimate forms plugin for wordpress
Be the first to know when new medium vulnerabilities affecting webaways nex-forms – ultimate forms plugin for wordpress are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
webaways / NEX-Forms – Ultimate Forms Plugin for WordPress
0 ≤ 7.7.1
References
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/01940eeb-b4a6-450d-b646-84f415ca92c9?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/2427162/ wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/01940eeb-b4a6-450d-b646-84f415ca92c9
Credits
Chloe Chamberland