Sceawere

Vulnerability Detail

CVE-2026-96607UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Reflected XSS in NEX-Forms

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
Basix
Product
NEX-Forms
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Reflected XSS.This issue affects NEX-Forms: from n/a through 9.3.1.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-09T10:16:45.557Z",
  "pubdate": "2026-10-09T10:16:45.557Z",
  "executiveSummary": "The NEX-Forms plugin for WordPress is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability, classified under CWE-79: Improper Neutralization of Input During Web Page Generation.\nThis security flaw allows an unauthenticated or authenticated attacker to inject and execute arbitrary JavaScript code within the context of a victim's web browser session.\nThe vulnerability exists in all versions of the NEX-Forms plugin from n/a through 9.3.1.\nSuccessful exploitation occurs when the application fails to adequately sanitize user-supplied input before reflecting it back to the user within the generated HTML response.\nAn attacker can leverage this vector to compromise user sessions, capture sensitive data such as session cookies or CSRF tokens, perform unauthorized actions on behalf of the victim, or facilitate phishing attacks.\nThe risk implication is high, as it grants the attacker the ability to manipulate the victim's interaction with the web application, leading to potential account takeover or data exfiltration.\nExploitation requires minimal interaction from the victim, typically involving the redirection of the user to a specially crafted URL containing the malicious payload.",
  "technicalDetails": "The root cause of this vulnerability is the improper neutralization of user-supplied data in the NEX-Forms plugin's rendering logic. Specifically, the application reflects input parameters directly into the server-generated HTML document without performing sufficient output encoding or context-aware sanitization.\nThe vulnerability manifests as a Reflected XSS (Cross-Site Scripting) flaw. Because the plugin does not implement adequate server-side input validation or output escaping for specific request parameters, an attacker can supply a crafted script payload via URL parameters. When a victim processes the malicious link, the vulnerable component processes the unsanitized input and incorporates it directly into the page source.\nThe execution flow is as follows: 1) An attacker identifies a vulnerable entry point in the NEX-Forms codebase where input parameters are processed and subsequently reflected. 2) The attacker crafts a URL containing a malicious JavaScript payload injected into these parameters. 3) The attacker induces the victim (e.g., an administrator or a standard user) to click the link or visit the page. 4) The application processes the request, receives the malicious payload, and reflects it back in the HTTP response. 5) The victim's browser interprets the payload as a legitimate script originating from the trusted domain and executes the code within the victim's session context.\nSince the payload is executed in the user's browser, the attacker inherits the victim's session privileges. This bypasses typical access control protections if the victim is an authenticated user. If the victim is a site administrator, the attacker could potentially execute administrative actions, modify settings, or install malicious content on the WordPress installation.\nAffected versions include all iterations from n/a to 9.3.1. There is no specific requirement for high-level privileges to initiate the reflection, making this a pervasive issue for any exposed installation. Post-exploitation impact includes persistent session hijacking, sensitive data exfiltration (including site-wide configuration data or user personal information), and the redirection of traffic to external malicious domains. The vulnerability remains active as long as the reflection point exists and the user input is treated as trusted content by the rendering engine."
}
CVE-2026-96607: Reflected XSS in NEX-Forms (HIGH Severity, CVSS: 7.1) | Sceawere