HomeWordPress vulnerabilitiesForm Maker by 10Web
Form Maker by 10Web vulnerabilities
Form Maker by 10Web has 32 known vulnerabilities in this database. The most recent published record is dated 1 Oct 2026.
- Known vulnerabilities
- 32
- Active installs
- 30,000+
- Latest version
- 1.15.48
- Last updated
- 28 Sep 2026
- Most recent
- 1 Oct 2026
No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Cross-site scripting (XSS) CVE-2026-96813 | High 7.2 | Up to 1.15.47 | Fixed in a later version (latest 1.15.48) | 6 d ago |
| Cross-site scripting (XSS) CVE-2026-85645 | Medium 6.1 | Up to 1.15.46 | Fixed in a later version (latest 1.15.48) | 10 Sep 2026 |
| Cross-site scripting (XSS) CVE-2026-66616 | High 7.1 | Up to 1.15.49 | No fixed version yet | 20 Aug 2026 |
| SQL injection CVE-2026-15993 | Medium 5.3 | Up to 1.15.44 | Fixed in a later version (latest 1.15.48) | 15 Aug 2026 |
| SQL injection CVE-2026-16977 | High 8.1 | Before 1.15.45 | Fixed in 1.15.45 | 12 Aug 2026 |
| SQL injection CVE-2026-11776 | Medium 4.9 | Up to 1.15.43 | Fixed in a later version (latest 1.15.48) | 18 Jun 2026 |
| SQL injection CVE-2026-11777 | Medium 4.9 | Up to 1.15.43 | Fixed in a later version (latest 1.15.48) | 18 Jun 2026 |
| SQL injection CVE-2026-3359 | High 7.5 | Up to 1.15.42 | Fixed in a later version (latest 1.15.48) | 5 May 2026 |
| SQL injection CVE-2026-3330 | Medium 4.9 | Up to 1.15.40 | Fixed in a later version (latest 1.15.48) | 17 Apr 2026 |
| Cross-site scripting (XSS) CVE-2026-4388 | High 7.2 | Up to 1.15.40 | Fixed in a later version (latest 1.15.48) | 14 Apr 2026 |
| SQL injection CVE-2025-15441 | Medium 6.8 | Before 1.15.38 | Fixed in 1.15.38 | 13 Apr 2026 |
| Cross-site scripting (XSS) CVE-2026-1058 | High 7.1 | Up to 1.15.35 | Fixed in a later version (latest 1.15.48) | 3 Feb 2026 |
| Cross-site scripting (XSS) CVE-2026-1065 | High 7.2 | Up to 1.15.35 | Fixed in a later version (latest 1.15.48) | 3 Feb 2026 |
| Cross-site scripting (XSS) CVE-2024-13053 | Medium 4.8 | Before 1.15.33 | Fixed in 1.15.33 | 15 May 2025 |
| Cross-site scripting (XSS) CVE-2024-10680 | Medium 4.8 | Before 1.15.32 | Fixed in 1.15.32 | 16 Apr 2025 |
| Cross-site scripting (XSS) CVE-2024-10560 | Low 3.5 | Before 1.15.30 | Fixed in 1.15.30 | 25 Mar 2025 |
| Cross-site scripting (XSS) CVE-2024-10558 | Low 3.5 | Before 1.15.30 | Fixed in 1.15.30 | 24 Mar 2025 |
| Cross-site scripting (XSS) CVE-2024-13605 | Medium 4.8 | Before 1.15.33 | Fixed in 1.15.33 | 24 Feb 2025 |
| Cross-site scripting (XSS) CVE-2024-10562 | Low 2.7 | Before 1.15.31 | Fixed in 1.15.31 | 7 Jan 2025 |
| Cross-site scripting (XSS) CVE-2024-10265 | Medium 6.1 | Before 1.15.31 | Fixed in 1.15.31 | 10 Nov 2024 |
| Cross-site scripting (XSS) CVE-2024-8633 | Medium 5.5 | Before 1.15.28 | Fixed in 1.15.28 | 26 Sep 2024 |
| Cross-site scripting (XSS) CVE-2024-6130 | Medium 4.8 | Before 1.15.26 | Fixed in 1.15.26 | 1 Jul 2024 |
| Cross-site scripting (XSS) CVE-2024-2258 | Medium 4.4 | Before 1.15.25 | Fixed in 1.15.25 | 27 Apr 2024 |
| Sensitive data exposure CVE-2024-2112 | Medium 5.9 | Before 1.15.23 | Fixed in 1.15.23 | 9 Apr 2024 |
| Cross-site request forgery (CSRF) CVE-2024-0667 | Medium 5.4 | Up to 1.15.21 | Fixed in a later version (latest 1.15.48) | 27 Jan 2024 |
| Remote code execution CVE-2023-4666 | Critical 9.8 | Before 1.15.20 | Fixed in 1.15.20 | 16 Oct 2023 |
| SQL injection CVE-2022-3300 | High 7.2 | Before 1.15.6 | Fixed in 1.15.6 | 25 Oct 2022 |
| Cross-site scripting (XSS) CVE-2022-1564 | Medium 4.8 | Up to 1.14.12 | Fixed in a later version (latest 1.15.48) | 30 May 2022 |
| Cross-site scripting (XSS) CVE-2021-24526 | Medium 5.4 | Before 1.13.60 | Fixed in 1.13.60 | 16 Aug 2021 |
| SQL injection CVE-2019-10866 | Critical 9.8 | Before 1.13.3 | Fixed in 1.13.3 | 23 May 2019 |
| Cross-site request forgery (CSRF) CVE-2019-11590 | High 8.8 | Before 1.13.5 | Fixed in 1.13.5 | 29 Apr 2019 |
| CSV injection CVE-2018-10504 | High 7.8 | Before 1.12.24 | Fixed in 1.12.24 | 27 Apr 2018 |
Read the published descriptions
- CVE-2026-96813, 1 Oct 2026
- The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2026-85645, 10 Sep 2026
- The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the bulk_action parameter in all versions up to, and including, 1.15.46 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
- CVE-2026-66616, 20 Aug 2026
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Maker by 10Web form-maker allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.49. CVE record
- CVE-2026-15993, 15 Aug 2026
- The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause in all versions up to, and including, 1.15.44 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This requires that a form is configured with a DB-backed dynamic choice field whose WHERE template references the {username} placeholder, and the attacker must first set their own display_name to a SQL payload via the standard WordPress profile edit screen before triggering the fm_reload_input AJAX endpoint. CVE record
- CVE-2026-16977, 12 Aug 2026
- The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection. CVE record
- CVE-2026-11776, 18 Jun 2026
- The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'groupids' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2026-11777, 18 Jun 2026
- The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'name' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2026-3359, 5 May 2026
- The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection via the 'inputs' parameter in versions up to, and including, 1.15.42 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2026-3330, 17 Apr 2026
- The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate', 'username_search', and 'useremail_search' parameters in all versions up to, and including, 1.15.40. This is due to the `WDW_FM_Library::validate_data()` method calling `stripslashes()` on user input (removing WordPress's `wp_magic_quotes()` protection) and the `FMModelSubmissions_fm::get_labels_parameters()` function directly concatenating user-supplied values into SQL queries without using `$wpdb->prepare()`. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Additionally, the Submissions controller skips nonce verification for the `display` task, which means this vulnerability can be triggered via CSRF by tricking an administrator into clicking a crafted link. CVE record
- CVE-2026-4388, 14 Apr 2026
- The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box input type) in form submissions in all versions up to, and including, 1.15.40. This is due to insufficient input sanitization (`sanitize_text_field` strips tags but not quotes) and missing output escaping when rendering submission data in the admin Submissions view. This makes it possible for unauthenticated attackers to inject arbitrary JavaScript through a form submission that executes in the browser of an administrator who views the submission details. CVE record
- CVE-2025-15441, 13 Apr 2026
- The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which could make SQL Injection attacks possible in certain contexts. CVE record
- CVE-2026-1058, 3 Feb 2026
- The Form Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via hidden field values in all versions up to, and including, 1.15.35. This is due to insufficient output escaping when displaying hidden field values in the admin submissions list. The plugin uses html_entity_decode() on user-supplied hidden field values without subsequent escaping before output, which converts HTML entity-encoded payloads back into executable JavaScript. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in the admin submissions view that will execute whenever an administrator accesses the submissions list. CVE record
- CVE-2026-1065, 3 Feb 2026
- The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.35. This is due to the plugin's default file upload allowlist including SVG files combined with weak substring-based extension validation. This makes it possible for unauthenticated attackers to upload malicious SVG files containing JavaScript code that will execute when viewed by administrators or site visitors via file upload fields in forms granted they can submit forms. CVE record
- CVE-2024-13053, 15 May 2025
- The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
- CVE-2024-10680, 16 Apr 2025
- The Form Maker by 10Web WordPress plugin before 1.15.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
- CVE-2024-10560, 25 Mar 2025
- The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
- CVE-2024-10558, 24 Mar 2025
- The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
- CVE-2024-13605, 24 Feb 2025
- The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
- CVE-2024-10562, 7 Jan 2025
- The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
- CVE-2024-10265, 10 Nov 2024
- The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.15.30. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
- CVE-2024-8633, 26 Sep 2024
- The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-6130, 1 Jul 2024
- The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) CVE record
- CVE-2024-2258, 27 Apr 2024
- The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name autofilled into forms in all versions up to, and including, 1.15.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-2112, 9 Apr 2024
- The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.15.22 via the signature functionality. This makes it possible for unauthenticated attackers to extract sensitive data including user signatures. CVE record
- CVE-2024-0667, 27 Jan 2024
- The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.15.21. This is due to missing or incorrect nonce validation on the 'execute' function. This makes it possible for unauthenticated attackers to execute arbitrary methods in the 'BoosterController' class via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
- CVE-2023-4666, 16 Oct 2023
- The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE CVE record
- CVE-2022-3300, 25 Oct 2022
- The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin CVE record
- CVE-2022-1564, 30 May 2022
- The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which could allow high privilege user such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed CVE record
- CVE-2021-24526, 16 Aug 2021
- The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue CVE record
- CVE-2019-10866, 23 May 2019
- In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter. CVE record
- CVE-2019-11590, 29 Apr 2019
- The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized. CVE record
- CVE-2018-10504, 27 Apr 2018
- The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection. CVE record
What to do if you run Form Maker by 10Web
If you run Form Maker by 10Web, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Form Maker by 10Web vulnerabilities
Free. We email you when a new vulnerability is published for Form Maker by 10Web, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.