Description
WordPress Plugin NEX-Forms-The Ultimate WordPress Form Builder is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently access PDF and Excel reports. WordPress Plugin NEX-Forms-The Ultimate WordPress Form Builder version 7.8.7 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 7.8.8 or latest
References
https://www.pentestfactory.de/en/vulnerabilities-in-nex-forms-7-8-8/
https://github.com/rauschecker/CVEs/tree/main/CVE-2021-34675
https://github.com/rauschecker/CVEs/tree/main/CVE-2021-34676
Related Vulnerabilities
WordPress Plugin RSS for Yandex Turbo Cross-Site Scripting (1.29)
Joomla! Core 3.x.x Security Bypass (3.7.0 - 3.8.11)
WordPress Plugin Pinblocks-Gutenberg blocks with Pinterest widgets Unspecified Vulnerability (1.0.1)
WordPress Plugin Comment Rating SQL Injection and Security Bypass Weakness Vulnerabilities (2.9.32)