Pricing
WordPress securityInstantly fix and mitigate vulnerabilitiesPlugin auditingPaid auditing for WordPress vendorsManaged VDPStart a security program for your pluginsBug BountyJoin the community and earn bountiesEnterprise APIAt scale monitoring and vPatching for hostsVulnerability databaseThe latest WordPress security intelligence
Login Start trial
Plugin Icon

NEX-Forms

Basix

Developer

9.1.7

Latest version

9,000

Installations

Sep 22, 2025

Last updated

WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
    Vulnerabilities

Vulnerability history

0 present
17 fixed
4 Mitigation rules
  • Authenticated (Admin+) SQL Injection vulnerability
    <= 9.1.6
    Oct 10, 2025
  • Cross Site Request Forgery (CSRF) Vulnerability
    <= 9.1.3
    Aug 20, 2025
  • Authenticated (Custom) Limited Code Execution via get_table_records Function vulnerability
    <= 8.9.1
    May 8, 2025
  • Authenticated (Custom) Stored Cross-Site Scripting vulnerability
    <= 8.9.1
    May 8, 2025
  • Unauthenticated Sensitive Information Exposure vulnerability
    <= 8.8.1
    Mar 11, 2025
  • Authenticated (Admin+) SQL Injection vulnerability
    <= 8.7.15
    Dec 24, 2024
  • SQL Injection vulnerability
    <= 8.7.8
    Dec 2, 2024
  • Reflected Cross Site Scripting (XSS) vulnerability
    <= 8.7.3
    Sep 30, 2024
  • Cross Site Scripting (XSS) vulnerability
    <= 8.5.10
    Jul 5, 2024
  • Cross Site Scripting (XSS) vulnerability
    <= 8.5.5
    Feb 12, 2024
  • Multiple Missing Authorization vulnerability
    <= 8.5.6
    Feb 1, 2024
  • Cross Site Request Forgery (CSRF) vulnerability
    <= 8.5.2
    Dec 28, 2023
  • SQL Injection vulnerability
    <= 8.5.5
    Dec 21, 2023
  • Auth. SQL Injection (SQLi) vulnerability
    < 8.4
    Apr 25, 2023
  • Contributor+ Stored XSS vulnerability
    < 8.3.3
    Mar 28, 2023
  • Authenticated SQL Injection (SQLi) vulnerability
    <= 7.9.6
    Aug 1, 2022
  • Multiple Stored Cross-Site Scripting (XSS) vulnerabilities
    <= 8.2
    Nov 15, 2021

Vulnerability mitigation

  • Pricing
  • Application security (SCA)
  • RapidMitigate New
  • Threat Intelligence (API)
  • Documentation
  • VS Monarx
  • VS Imunify360
  • VS Wordfence
  • Log in

Code security

  • Managed VDP New
  • Active VDP directory
  • Security auditing
  • Compliance (CRA) New
  • Log in New

Bug bounty

  • Bug bounty
  • Leaderboard
  • Guidelines
  • Learn New
  • Report
  • Discord
  • Log in New

Use cases

  • Web developers
  • Webhosts New
  • Software vendors
  • WordPress
  • WooCommerce

Resources

  • Vulnerability database
  • Whitepaper 2025 New
  • Articles
  • Case studies New
  • Webinars New
  • Vulnerability statistics

Patchstack

  • About
  • Careers
  • Merch store
  • Media kit
  • LinkedIn
  • Facebook
  • X
© 2025 Patchstack
DPA
Privacy Policy
Accessibility
Terms & Conditions
EU Flag