Reflected Cross-Site Scripting Vulnerability in Form Maker by 10Web for WordPress
CVE-2026-103998
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-103998?
The Form Maker by 10Web plugin for WordPress is susceptible to Reflected Cross-Site Scripting due to inadequate input sanitization and output escaping. Attackers can exploit this vulnerability by manipulating the 'inputs (array key)' parameter to inject malicious scripts. If a user is tricked into clicking a specially crafted link, the injected scripts may execute in their browser, potentially compromising sensitive information and user sessions.
Affected Version(s)
Form Maker by 10Web β Mobile-Friendly Drag & Drop Contact Form Builder 0 <= 1.15.48