CVE-2026-13040 | webaways NEX-Forms Plugin up to 9.2.2 on WordPress Submission Endpoint real_val__ cross site scripting (EUVD-2026-41487)

SecurityVulns

A vulnerability classified as problematic was found in webaways NEX-Forms Plugin up to 9.2.2 on WordPress. This affects an unknown function of the component Submission Endpoint. Executing a manipulation of the argument real_val__ can lead to cross site scripting.

The identification of this vulnerability is CVE-2026-13040. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More