CVE-2026-57668

HIGH

WordPress NEX-Forms plugin <= 9.2.2 - Cross Site Scripting (XSS) vulnerability

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-57668. PoCs published by incogbyte.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-57668, an unauthenticated stored XSS vulnerability in NEX-Forms Express WP Form Builder <= 9.2.2. The exploit demonstrates how array-typed form field submissions bypass sanitization, allowing raw script tags to be stored and later executed in an admin's browser session.

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Stored XSS.This issue affects NEX-Forms: from n/a through <= 9.2.2.

Exploits (1)

github WORKING POC 3 stars
by incogbyte · pythonpoc
https://github.com/incogbyte/wp-cve-exploits/tree/main/CVE-2026-57668

This repository contains a functional exploit for CVE-2026-57668, an unauthenticated stored XSS vulnerability in NEX-Forms Express WP Form Builder <= 9.2.2. The exploit demonstrates how array-typed form field submissions bypass sanitization, allowing raw script tags to be stored and later executed in an admin's browser session.

Classification
Working Poc 99%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: NEX-Forms Express WP Form Builder <= 9.2.2
No auth needed
Prerequisites: Target must have a published NEX-Forms form with a known form ID · Admin credentials to verify the stored payload execution (optional for full PoC)
mistral-large-3 · analyzed Jul 14, 2026 Full analysis →

Scores

CVSS v3 7.1
EPSS 0.0018
EPSS Percentile 7.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
Basix/NEX-Forms < 9.2.2
Published Jul 13, 2026
Tracked Since Jul 13, 2026