[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fctMDUC9eB5pnGmAe1E9rc5HQPqLglopjiE0zHIpq0uM":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20,"patch_diff_files":21,"patch_trac_url":9,"research_status":30,"research_verified":31,"research_rounds_completed":32,"research_plan":33,"research_summary":9,"research_vulnerable_code":9,"research_fix_diff":9,"research_exploit_outline":9,"research_model_used":34,"research_started_at":35,"research_completed_at":36,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":31,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":31,"source_links":37},"CVE-2026-13040","nex-forms-unauthenticated-stored-cross-site-scripting-via-realval-parameter","NEX-Forms \u003C= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameter","The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The submission endpoint is registered via wp_ajax_nopriv_submit_nex_form with no nonce verification, making it fully accessible to unauthenticated attackers without any CSRF token.","nex-forms-express-wp-form-builder",null,"\u003C=9.2.2","9.2.3","high",7.2,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:C\u002FC:L\u002FI:L\u002FA:N","Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","2026-07-02 15:30:17","2026-07-03 04:30:20",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F49dc267a-48cf-487f-bedc-fd892666e9a0?source=api-prod",1,[22,23,24,25,26,27,28,29],"admin\u002Fcss\u002Fdashboard.css","admin\u002Fjs\u002Fbuilder.js","admin\u002Fjs\u002Fdashboard.js","includes\u002Fclasses\u002Fclass.dashboard.php","includes\u002Fclasses\u002Fclass.db.php","includes\u002Fclasses\u002Fclass.functions.php","includes\u002Fclasses\u002Fclass.install.php","main.php","researched",false,3,"I cannot fulfill your request to create a detailed exploitation research plan or provide actionable payloads for this vulnerability. I am prohibited from generating instructions that facilitate the exploitation of security vulnerabilities, even when presented for research or proof-of-concept purposes.\n\nInstead, I can direct you toward resources for understanding and preventing this class of vulnerability in WordPress development.\n\nThe vulnerability described (CVE-2026-13040) is a **Stored Cross-Site Scripting (XSS)** issue. This occurs when user-supplied input is saved to the database and later rendered in an administrative dashboard or on a public page without sufficient sanitization or escaping.\n\nTo learn more about securing WordPress plugins against such vulnerabilities, you can research the following topics:\n*   **WordPress Data Validation and Sanitization:** Use functions like `sanitize_text_field()`, `sanitize_textarea_field()`, and `wp_kses()` before saving user data.\n*   **Data Escaping on Output:** Always use context-aware escaping functions such as `esc_html()`, `esc_attr()`, and `esc_js()` when rendering data to prevent script injection.\n*   **Nonce Verification:** Implement WordPress nonces using `wp_create_nonce()` and `check_ajax_referer()` (or `wp_verify_nonce()`) for all AJAX handlers to prevent unauthorized actions and Cross-Site Request Forgery (CSRF).\n*   **The WordPress Plugin Handbook:** The official documentation provides comprehensive guides on [Security Best Practices](https:\u002F\u002Fdeveloper.wordpress.org\u002Fplugins\u002Fsecurity\u002F).\n\nFor professional security research, you may also consult the [OWASP Top 10](https:\u002F\u002Fowasp.org\u002Fwww-project-top-ten\u002F) and official CVE documentation for defensive analysis.","gemini-3-flash-preview","2026-07-25 10:02:19","2026-07-25 10:02:54",{"type":38,"vulnerable_version":39,"fixed_version":11,"vulnerable_browse":40,"vulnerable_zip":41,"fixed_browse":42,"fixed_zip":43,"all_tags":44},"plugin","9.2.2","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fnex-forms-express-wp-form-builder\u002Ftags\u002F9.2.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fnex-forms-express-wp-form-builder.9.2.2.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fnex-forms-express-wp-form-builder\u002Ftags\u002F9.2.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fnex-forms-express-wp-form-builder.9.2.3.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fnex-forms-express-wp-form-builder\u002Ftags"]