Description
WordPress Plugin NEX-Forms-The Ultimate WordPress Form Builder is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently access PDF and Excel reports. WordPress Plugin NEX-Forms-The Ultimate WordPress Form Builder version 7.8.7 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 7.8.8 or latest
References
https://www.pentestfactory.de/en/vulnerabilities-in-nex-forms-7-8-8/
https://github.com/rauschecker/CVEs/tree/main/CVE-2021-34675
https://github.com/rauschecker/CVEs/tree/main/CVE-2021-34676
Related Vulnerabilities
WordPress Plugin Duplicate Post Cross-Site Scripting (2.6)
WordPress Plugin WooCommerce Cross-Site Scripting (2.2.10)
Apache Tomcat Improper Locking Vulnerability (CVE-2019-10072)
WordPress Plugin Email Before Download SQL Injection (6.7)
Oracle Application Server CVE-2008-2589 Vulnerability (CVE-2008-2589)