Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesForm Maker by 10Web

Form Maker by 10Web vulnerabilities

Form Maker by 10Web has 32 known vulnerabilities in this database. The most recent published record is dated 1 Oct 2026.

Known vulnerabilities
32
Active installs
30,000+
Latest version
1.15.48
Last updated
28 Sep 2026
Most recent
1 Oct 2026

No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Cross-site scripting (XSS)
CVE-2026-96813
High 7.2Up to 1.15.47Fixed in a later version (latest 1.15.48)6 d ago
Cross-site scripting (XSS)
CVE-2026-85645
Medium 6.1Up to 1.15.46Fixed in a later version (latest 1.15.48)10 Sep 2026
Cross-site scripting (XSS)
CVE-2026-66616
High 7.1Up to 1.15.49No fixed version yet20 Aug 2026
SQL injection
CVE-2026-15993
Medium 5.3Up to 1.15.44Fixed in a later version (latest 1.15.48)15 Aug 2026
SQL injection
CVE-2026-16977
High 8.1Before 1.15.45Fixed in 1.15.4512 Aug 2026
SQL injection
CVE-2026-11776
Medium 4.9Up to 1.15.43Fixed in a later version (latest 1.15.48)18 Jun 2026
SQL injection
CVE-2026-11777
Medium 4.9Up to 1.15.43Fixed in a later version (latest 1.15.48)18 Jun 2026
SQL injection
CVE-2026-3359
High 7.5Up to 1.15.42Fixed in a later version (latest 1.15.48)5 May 2026
SQL injection
CVE-2026-3330
Medium 4.9Up to 1.15.40Fixed in a later version (latest 1.15.48)17 Apr 2026
Cross-site scripting (XSS)
CVE-2026-4388
High 7.2Up to 1.15.40Fixed in a later version (latest 1.15.48)14 Apr 2026
SQL injection
CVE-2025-15441
Medium 6.8Before 1.15.38Fixed in 1.15.3813 Apr 2026
Cross-site scripting (XSS)
CVE-2026-1058
High 7.1Up to 1.15.35Fixed in a later version (latest 1.15.48)3 Feb 2026
Cross-site scripting (XSS)
CVE-2026-1065
High 7.2Up to 1.15.35Fixed in a later version (latest 1.15.48)3 Feb 2026
Cross-site scripting (XSS)
CVE-2024-13053
Medium 4.8Before 1.15.33Fixed in 1.15.3315 May 2025
Cross-site scripting (XSS)
CVE-2024-10680
Medium 4.8Before 1.15.32Fixed in 1.15.3216 Apr 2025
Cross-site scripting (XSS)
CVE-2024-10560
Low 3.5Before 1.15.30Fixed in 1.15.3025 Mar 2025
Cross-site scripting (XSS)
CVE-2024-10558
Low 3.5Before 1.15.30Fixed in 1.15.3024 Mar 2025
Cross-site scripting (XSS)
CVE-2024-13605
Medium 4.8Before 1.15.33Fixed in 1.15.3324 Feb 2025
Cross-site scripting (XSS)
CVE-2024-10562
Low 2.7Before 1.15.31Fixed in 1.15.317 Jan 2025
Cross-site scripting (XSS)
CVE-2024-10265
Medium 6.1Before 1.15.31Fixed in 1.15.3110 Nov 2024
Cross-site scripting (XSS)
CVE-2024-8633
Medium 5.5Before 1.15.28Fixed in 1.15.2826 Sep 2024
Cross-site scripting (XSS)
CVE-2024-6130
Medium 4.8Before 1.15.26Fixed in 1.15.261 Jul 2024
Cross-site scripting (XSS)
CVE-2024-2258
Medium 4.4Before 1.15.25Fixed in 1.15.2527 Apr 2024
Sensitive data exposure
CVE-2024-2112
Medium 5.9Before 1.15.23Fixed in 1.15.239 Apr 2024
Cross-site request forgery (CSRF)
CVE-2024-0667
Medium 5.4Up to 1.15.21Fixed in a later version (latest 1.15.48)27 Jan 2024
Remote code execution
CVE-2023-4666
Critical 9.8Before 1.15.20Fixed in 1.15.2016 Oct 2023
SQL injection
CVE-2022-3300
High 7.2Before 1.15.6Fixed in 1.15.625 Oct 2022
Cross-site scripting (XSS)
CVE-2022-1564
Medium 4.8Up to 1.14.12Fixed in a later version (latest 1.15.48)30 May 2022
Cross-site scripting (XSS)
CVE-2021-24526
Medium 5.4Before 1.13.60Fixed in 1.13.6016 Aug 2021
SQL injection
CVE-2019-10866
Critical 9.8Before 1.13.3Fixed in 1.13.323 May 2019
Cross-site request forgery (CSRF)
CVE-2019-11590
High 8.8Before 1.13.5Fixed in 1.13.529 Apr 2019
CSV injection
CVE-2018-10504
High 7.8Before 1.12.24Fixed in 1.12.2427 Apr 2018
Read the published descriptions
CVE-2026-96813, 1 Oct 2026
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-85645, 10 Sep 2026
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the bulk_action parameter in all versions up to, and including, 1.15.46 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
CVE-2026-66616, 20 Aug 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Maker by 10Web form-maker allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.49. CVE record
CVE-2026-15993, 15 Aug 2026
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause in all versions up to, and including, 1.15.44 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This requires that a form is configured with a DB-backed dynamic choice field whose WHERE template references the {username} placeholder, and the attacker must first set their own display_name to a SQL payload via the standard WordPress profile edit screen before triggering the fm_reload_input AJAX endpoint. CVE record
CVE-2026-16977, 12 Aug 2026
The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection. CVE record
CVE-2026-11776, 18 Jun 2026
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'groupids' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2026-11777, 18 Jun 2026
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'name' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2026-3359, 5 May 2026
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection via the 'inputs' parameter in versions up to, and including, 1.15.42 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2026-3330, 17 Apr 2026
The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate', 'username_search', and 'useremail_search' parameters in all versions up to, and including, 1.15.40. This is due to the `WDW_FM_Library::validate_data()` method calling `stripslashes()` on user input (removing WordPress's `wp_magic_quotes()` protection) and the `FMModelSubmissions_fm::get_labels_parameters()` function directly concatenating user-supplied values into SQL queries without using `$wpdb->prepare()`. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Additionally, the Submissions controller skips nonce verification for the `display` task, which means this vulnerability can be triggered via CSRF by tricking an administrator into clicking a crafted link. CVE record
CVE-2026-4388, 14 Apr 2026
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box input type) in form submissions in all versions up to, and including, 1.15.40. This is due to insufficient input sanitization (`sanitize_text_field` strips tags but not quotes) and missing output escaping when rendering submission data in the admin Submissions view. This makes it possible for unauthenticated attackers to inject arbitrary JavaScript through a form submission that executes in the browser of an administrator who views the submission details. CVE record
CVE-2025-15441, 13 Apr 2026
The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which could make SQL Injection attacks possible in certain contexts. CVE record
CVE-2026-1058, 3 Feb 2026
The Form Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via hidden field values in all versions up to, and including, 1.15.35. This is due to insufficient output escaping when displaying hidden field values in the admin submissions list. The plugin uses html_entity_decode() on user-supplied hidden field values without subsequent escaping before output, which converts HTML entity-encoded payloads back into executable JavaScript. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in the admin submissions view that will execute whenever an administrator accesses the submissions list. CVE record
CVE-2026-1065, 3 Feb 2026
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.35. This is due to the plugin's default file upload allowlist including SVG files combined with weak substring-based extension validation. This makes it possible for unauthenticated attackers to upload malicious SVG files containing JavaScript code that will execute when viewed by administrators or site visitors via file upload fields in forms granted they can submit forms. CVE record
CVE-2024-13053, 15 May 2025
The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
CVE-2024-10680, 16 Apr 2025
The Form Maker by 10Web WordPress plugin before 1.15.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
CVE-2024-10560, 25 Mar 2025
The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
CVE-2024-10558, 24 Mar 2025
The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
CVE-2024-13605, 24 Feb 2025
The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
CVE-2024-10562, 7 Jan 2025
The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE record
CVE-2024-10265, 10 Nov 2024
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.15.30. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. CVE record
CVE-2024-8633, 26 Sep 2024
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-6130, 1 Jul 2024
The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) CVE record
CVE-2024-2258, 27 Apr 2024
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name autofilled into forms in all versions up to, and including, 1.15.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-2112, 9 Apr 2024
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.15.22 via the signature functionality. This makes it possible for unauthenticated attackers to extract sensitive data including user signatures. CVE record
CVE-2024-0667, 27 Jan 2024
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.15.21. This is due to missing or incorrect nonce validation on the 'execute' function. This makes it possible for unauthenticated attackers to execute arbitrary methods in the 'BoosterController' class via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
CVE-2023-4666, 16 Oct 2023
The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE CVE record
CVE-2022-3300, 25 Oct 2022
The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin CVE record
CVE-2022-1564, 30 May 2022
The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which could allow high privilege user such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed CVE record
CVE-2021-24526, 16 Aug 2021
The Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue CVE record
CVE-2019-10866, 23 May 2019
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter. CVE record
CVE-2019-11590, 29 Apr 2019
The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized. CVE record
CVE-2018-10504, 27 Apr 2018
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection. CVE record

What to do if you run Form Maker by 10Web

If you run Form Maker by 10Web, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Form Maker by 10Web vulnerabilities

Free. We email you when a new vulnerability is published for Form Maker by 10Web, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support