{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/nex-forms--ultimate-form-builder--lite--9.2.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-15450"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Nex Forms – Ultimate Form Builder – Lite (\u003c= 9.2.3)"],"_cs_severities":["high"],"_cs_tags":["wordpress","arbitrary-file-deletion","path-traversal","web-application"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Nex Forms - Ultimate Form Builder - Lite plugin for WordPress (versions 9.2.3 and below) contains a critical path traversal vulnerability that enables arbitrary file deletion. The vulnerability exists within two specific AJAX handlers: insert_record() and delete_file(). The insert_record() function fails to validate input before storing it in the database, allowing an attacker to inject malicious file paths. The delete_file() function then retrieves this unsanitized path and passes it directly to the PHP unlink() function without performing path normalization, basename validation, or allowlist checks.\u003c/p\u003e\n\u003cp\u003eThis flaw allows authenticated users - typically those with administrative privileges, though potentially lower depending on plugin configuration - to delete arbitrary files on the underlying web server. Successful exploitation can result in the deletion of critical WordPress files such as wp-config.php, which effectively forces a site re-installation or results in a complete denial of service. The vulnerability highlights the danger of passing user-supplied input directly to filesystem-modifying functions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the deletion of critical server files. In the context of a WordPress environment, the deletion of the wp-config.php file removes database connection settings, causing the site to become inaccessible and potentially allowing an attacker to initiate a fresh installation or redirect the site traffic. This poses a high risk to availability and system integrity for organizations relying on this plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Nex Forms - Ultimate Form Builder - Lite plugin to the latest version immediately to patch CVE-2026-15450.\u003c/li\u003e\n\u003cli\u003eAudit the WordPress plugin directory and remove any plugins that are not actively maintained or required for business operations.\u003c/li\u003e\n\u003cli\u003eImplement restrictive file system permissions on the web server to ensure that the web service user (e.g., www-data) cannot delete critical configuration or system files outside of designated upload directories.\u003c/li\u003e\n\u003cli\u003eReview WordPress access logs for anomalous POST requests directed at the plugin's AJAX endpoints if indicators of compromise are suspected.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-01T09:50:07Z","date_published":"2026-08-01T09:50:07Z","id":"https://feed.craftedsignal.io/briefs/2026-08-nex-forms-traversal/","summary":"The Nex Forms - Ultimate Form Builder - Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal, allowing authenticated attackers to delete critical system files.","title":"Arbitrary File Deletion in Nex Forms Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-08-nex-forms-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Nex Forms – Ultimate Form Builder – Lite (\u003c= 9.2.3)","version":"https://jsonfeed.org/version/1.1"}