Blind SQL Injection Vulnerability in Form Maker Plugin by 10Web
CVE-2026-15993

5.3MEDIUM

What is CVE-2026-15993?

The Form Maker by 10Web is susceptible to a blind SQL Injection vulnerability stemming from insufficient escaping of the user-supplied parameter in the WHERE clause of dynamic-choice fields. Authenticated attackers with subscriber-level access can exploit this flaw by appending malicious SQL queries, consequently extracting sensitive database information. This exploitation necessitates a specific configuration where the dynamic choice field refers to the {username} placeholder, combined with the attacker setting their display_name to a SQL payload via the WordPress profile edit screen before invoking the fm_reload_input AJAX endpoint.

Affected Version(s)

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder 0 <= 1.15.44

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

R4mbb
.