Description
WordPress Plugin NEX-Forms-The Ultimate WordPress Form Builder is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently access PDF and Excel reports. WordPress Plugin NEX-Forms-The Ultimate WordPress Form Builder version 7.8.7 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 7.8.8 or latest
References
https://www.pentestfactory.de/en/vulnerabilities-in-nex-forms-7-8-8/
https://github.com/rauschecker/CVEs/tree/main/CVE-2021-34675
https://github.com/rauschecker/CVEs/tree/main/CVE-2021-34676
Related Vulnerabilities
WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Request Forgery (1.22.24)
MySQL CVE-2015-4830 Vulnerability (CVE-2015-4830)
ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-2086)
WordPress Plugin Improved Product Options for WooCommerce Security Bypass (5.2.0)