CVE-2026-1947General

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 9.1.9 via the submit_nex_form() function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to to overwrite arbitrary form entries via the 'nf_set_entry_update_id' parameter.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-17: 103-17
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
Full discourse1 post
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-1947 - webaways - NEX-Forms – Ultimate Forms Plugin for WordPress - https://www.redpacketsecurity.com/cve-alert-cve-2026-1947-webaways-nex-forms-ultimate-forms-plugin-for-wordpress/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-1947 #webaways #nex-forms-ultimate-forms-plugin-for-wordpress

    Post summary

    The post announces a CVE alert for a WordPress plugin but provides no substantive technical, exploit, or mitigation information.

    0000099
    3.6K followersView on X

Explore more