SQL Injection Vulnerability in Form Maker Plugin by 10Web
CVE-2026-11777

4.9MEDIUM

What is CVE-2026-11777?

The Form Maker plugin by 10Web for WordPress is susceptible to a SQL Injection vulnerability due to inadequate parameter escaping and insufficient preparation of the SQL query. This issue affects all versions up to and including 1.15.43. Authenticated attackers with administrator-level access can exploit this vulnerability by injecting malicious SQL queries through the 'name' parameter. This manipulation enables them to extract sensitive information from the database, posing a significant security risk.

Affected Version(s)

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder 0 <= 1.15.43

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Arsalan Diponegoro
.