CVE-2015-9452 | nex-forms-express-wp-form-builder Plugin up to 4.6.0 on WordPress admin.php?page=nex-forms-main nex_forms_Id sql injection
A vulnerability was found in nex-forms-express-wp-form-builder Plugin up to 4.6.0 on WordPress. It has been classified as critical. Affected is an unknown function of the file wp-admin/admin.php?page=nex-forms-main. The manipulation of the argument nex_forms_Id as part of Parameter leads to sql injection.
This vulnerability is traded as CVE-2015-9452. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.