Description
WordPress Plugin NEX-Forms-The Ultimate WordPress Form Builder is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently access PDF and Excel reports. WordPress Plugin NEX-Forms-The Ultimate WordPress Form Builder version 7.8.7 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 7.8.8 or latest
References
https://www.pentestfactory.de/en/vulnerabilities-in-nex-forms-7-8-8/
https://github.com/rauschecker/CVEs/tree/main/CVE-2021-34675
https://github.com/rauschecker/CVEs/tree/main/CVE-2021-34676