CVE-2026-9017
Deferred Deferred - Pending Action

Authorization Bypass in NEX-Forms WordPress Plugin

Vulnerability report for CVE-2026-9017, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-11

Last updated on: 2026-07-15

Assigner: Wordfence

Description

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the saved_admin_email, saved_user_email, and saved_user_email_address fields of arbitrary form entries belonging to other users, and cause the site to dispatch attacker-controlled email content to attacker-chosen recipient addresses.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-11
Last Modified
2026-07-15
Generated
2026-07-31
AI Q&A
2026-07-11
EPSS Evaluated
2026-07-30
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
nex-forms ultimate_forms_plugin to 9.2.2 (inc)
wpforms nex-forms to 9.2.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The NEX-Forms – Ultimate Forms Plugin for WordPress is vulnerable to an authorization bypass in all versions up to and including 9.2.2. This means the plugin does not properly verify whether a user is authorized to perform certain actions.

As a result, unauthenticated attackers can overwrite specific fields (saved_admin_email, saved_user_email, and saved_user_email_address) in form entries that belong to other users.

This allows attackers to cause the site to send email content controlled by them to recipient addresses of their choosing.

Impact Analysis

This vulnerability can allow attackers to send emails from your site with content and recipients they control.

Such unauthorized email dispatch could be used for phishing, spam, or other malicious activities that damage your site's reputation and trustworthiness.

Since the attacker can overwrite email fields of other users' form entries, it may also lead to confusion or misuse of user data.

Compliance Impact

The vulnerability allows unauthenticated attackers to overwrite email fields in form entries and send attacker-controlled email content to arbitrary recipients. This unauthorized access and manipulation of user data could potentially lead to violations of data protection regulations such as GDPR and HIPAA, which require strict controls over personal data and user consent.

However, the provided context does not explicitly state the impact on compliance with these standards.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9017. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart