CVE detail
CVE-2026-12404
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to enumerate sequential report IDs and download complete form submission data — including names, email addresses, phone numbers, postal addresses, payment details, and uploaded file paths — for any saved report on the site.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 23.0 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
9 source links · newest first
- Wordfence Intelligence Weekly WordPress Vulnerability Report (June 22, 2026 to June 28, 2026)Wordfence
SMTP HD Quiz 2.2.0 - 2.2.1 - Cross-Site Request Forgery via Multiple AJAX Handlers 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-13422 Patch Status Patched Published Jun 26, 2026 Affected Software HD Quiz [hd-quiz] Researcher Wordfence PRISM More Details > Job Portal Job Portal Kali Forms LatePoint Live Copy Paste for Elementor – Cross Domain Copy Past
vendorwww.wordfence.comJul 2, 2026, 6:34 PM - https://www.wordfence.com/threat-intel/vulnerabilities/id/ecf39f38-a476-47a8-a632-986b851895a6?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comJun 27, 2026, 6:16 AM - https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3584399%40nex-forms-express-wp-form-builder&new=3584399%40nex-forms-express-wp-form-builder&sfp_email=&sfph_mail=plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 27, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.2/main.php#L3792plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 27, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.2/main.php#L3654plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 27, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.2.2/main.php#L3648plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 27, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.12/main.php#L3792plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 27, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.12/main.php#L3654plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 27, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/nex-forms-express-wp-form-builder/tags/9.1.12/main.php#L3648plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 27, 2026, 6:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-73843CVSS 9.6 · Critical
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the e…
- CVE-2026-73842CVSS 9.0 · Critical
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/,…
- CVE-2026-73665CVSS 9.3 · Critical
FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies that mi…
- CVE-2026-73658CVSS 8.2 · High
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() i…
- CVE-2026-73305CVSS 8.8 · High
Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.appId in…
- CVE-2026-73656CVSS 9.9 · Critical
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateD…