The NEX-Forms WordPress plugin before 9.1.8 does not sanitise and escape some of its settings. The NEX-Forms WordPress plugin before 9.1.8 can be configured in such a way that could allow subscribers to perform Stored Cross-Site Scripting.
We have discovered 680 live websites that are affected by CVE-2025-14803.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 680 live websites (93% of Nex Forms Express Wp Form Builder install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 35 versions ( 95% of all versions) |
| 187 websites | |
| 144 websites | |
| 28 websites | |
| 27 websites | |
| 26 websites | |
| 26 websites | |
| 24 websites | |
| 22 websites | |
| 21 websites | |
| 15 websites |
| .com | 264 websites |
| .de | 97 websites |
| .nl | 29 websites |
| .at | 24 websites |
| .org | 24 websites |
| .com.au | 22 websites |
| .it | 16 websites |
| .co.uk | 13 websites |
| .fr | 13 websites |
| .ca | 10 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.de | ***,*** | ||
| ******.at | ***,*** | ||
| *********.be | *,***,*** | ||
| *************.com | *,***,*** | ||
| *******.***.za | *,***,*** | ||
| ****************.nl | *,***,*** | ||
| ********.com | *,***,*** | ||
| *****.***.za | *,***,*** | ||
| **************.com | *,***,*** | ||
| **************.de | *,***,*** |
FAQ