CVE-2025-10185 | webaways NEX-Forms Plugin up to 9.1.6 on WordPress nf_load_form_entries orderby sql injection (EUVD-2025-33815)
A vulnerability described as critical has been identified in webaways NEX-Forms Plugin up to 9.1.6 on WordPress. This affects the function nf_load_form_entries. Such manipulation of the argument orderby leads to sql injection.
This vulnerability is uniquely identified as CVE-2025-10185. The attack can be launched remotely. No exploit exists.