The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.8.1 via file uploads due to insufficient directory listing prevention and lack of randomization of file names. This makes it possible for unauthenticated attackers to extract sensitive data including files uploaded via a form.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Mar 2025 05:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.8.1 via file uploads due to insufficient directory listing prevention and lack of randomization of file names. This makes it possible for unauthenticated attackers to extract sensitive data including files uploaded via a form. | |
Title | NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.8.1 - Unauthenticated Sensitive Information Exposure | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-03-12T05:22:52.045Z
Updated: 2025-03-12T05:22:52.045Z
Reserved: 2025-01-16T21:29:59.055Z
Link: CVE-2024-13498

No data.

Status : Received
Published: 2025-03-12T06:15:21.360
Modified: 2025-03-12T06:15:21.360
Link: CVE-2024-13498

No data.