CVE-2026-15450 | webaways Nex Forms Plugin up to 9.2.3 on WordPress AJAX delete_file path traversal

SecurityVulns

A vulnerability described as problematic has been identified in webaways Nex Forms Plugin up to 9.2.3 on WordPress. Affected is the function delete_file of the component AJAX Handler. Such manipulation leads to path traversal.

This vulnerability is listed as CVE-2026-15450. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More