What is CVE-2026-15602?
CVE-2026-15602 is a generic SQL Injection vulnerability in the NEX-Forms – Ultimate Forms Plugin for WordPress, affecting all versions up to 9.2.4 via the 'additional_params' parameter. This is due to insufficient escaping and preparation on user-supplied data. Users should immediately update the plugin to the latest version.
Azərbaycanca: CVE-2026-15602 NEX-Forms – Ultimate Forms Plugin for WordPress plaginində 'additional_params' parametri vasitəsilə SQL Injection zəifliyidir. Bu, 9.2.4-ə qədər bütün versiyalara təsir edir. İstifadəçilər dərhal plaqini ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the NEX-Forms plugin are affected by CVE-2026-15602?
This vulnerability affects all versions of the NEX-Forms – Ultimate Forms Plugin for WordPress up to 9.2.4.
Which parameter is exploited in CVE-2026-15602?
The vulnerability allows SQL Injection via the 'additional_params' parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.