Blind SQL Injection Vulnerability in Form Maker Plugin by 10Web
CVE-2026-15993
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 August 2026
What is CVE-2026-15993?
The Form Maker by 10Web is susceptible to a blind SQL Injection vulnerability stemming from insufficient escaping of the user-supplied parameter in the WHERE clause of dynamic-choice fields. Authenticated attackers with subscriber-level access can exploit this flaw by appending malicious SQL queries, consequently extracting sensitive database information. This exploitation necessitates a specific configuration where the dynamic choice field refers to the {username} placeholder, combined with the attacker setting their display_name to a SQL payload via the WordPress profile edit screen before invoking the fm_reload_input AJAX endpoint.
Affected Version(s)
Form Maker by 10Web β Mobile-Friendly Drag & Drop Contact Form Builder 0 <= 1.15.44