SQL Injection Vulnerability in Form Maker Plugin by 10Web
CVE-2026-11777
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 June 2026
What is CVE-2026-11777?
The Form Maker plugin by 10Web for WordPress is susceptible to a SQL Injection vulnerability due to inadequate parameter escaping and insufficient preparation of the SQL query. This issue affects all versions up to and including 1.15.43. Authenticated attackers with administrator-level access can exploit this vulnerability by injecting malicious SQL queries through the 'name' parameter. This manipulation enables them to extract sensitive information from the database, posing a significant security risk.
Affected Version(s)
Form Maker by 10Web β Mobile-Friendly Drag & Drop Contact Form Builder 0 <= 1.15.43