Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 03 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webaways
Webaways nex-forms-ultimate-forms-plugin Wordpress Wordpress wordpress |
|
| Vendors & Products |
Webaways
Webaways nex-forms-ultimate-forms-plugin Wordpress Wordpress wordpress |
Sat, 01 Aug 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from the database and passing it directly to unlink() with no validation (no realpath(), basename(), or allowlist check), combined with the insert_record() AJAX handler that lets the same authenticated user store an arbitrary value in the target 'location' column (wp_kses() only strips HTML tags and does not neutralize path traversal or absolute paths). This makes it possible for authenticated attackers, with admin-level access and above, to delete arbitrary files on the affected site's server, including wp-config. When the plugin's user-level option is configured to something else, this may be exploitable with lower privileges. | |
| Title | NEX-Forms <= 9.2.3 - Authenticated (Admin+) Arbitrary File Deletion via Path Traversal via 'location' Parameter | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-08-03T19:25:59.037Z
Reserved: 2026-07-10T19:27:33.129Z
Link: CVE-2026-15450
Updated: 2026-08-03T19:25:54.548Z
Status : Deferred
Published: 2026-08-01T09:16:59.023
Modified: 2026-08-12T21:00:37.147
Link: CVE-2026-15450
No data.
OpenCVE Enrichment
Updated: 2026-08-04T11:30:07Z