What is CVE-2026-15450?
CVE-2026-15450 is an arbitrary file deletion vulnerability via path traversal in the Nex Forms – Ultimate Form Builder – Lite plugin for WordPress up to version 9.2.3. The flaw in the delete_file() AJAX handler allows attackers to delete sensitive files on the server. Immediate update to the latest plugin version is required.
Azərbaycanca: CVE-2026-15450, WordPress üçün Nex Forms – Ultimate Form Builder – Lite plagininin 9.2.3-ə qədər versiyalarında path traversal vasitəsilə ixtiyari fayl silməyə imkan verən boşluqdur. Təcavüzkar delete_file() AJAX funksiyasındakı zəiflikdən istifadə edərək serverdəki həssas faylları silə bilər. Plugin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which WordPress plugin is affected by CVE-2026-15450?
The vulnerability affects the Nex Forms – Ultimate Form Builder – Lite plugin up to version 9.2.3.
What can an attacker do by exploiting CVE-2026-15450?
An attacker can delete sensitive files on the server by exploiting the path traversal flaw in the delete_file() AJAX handler.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.