Reflected Cross-Site Scripting Vulnerability in Form Maker by 10Web
CVE-2026-85645
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 September 2026
What is CVE-2026-85645?
The Form Maker by 10Web plugin, a tool for creating mobile-friendly contact forms on WordPress sites, has a vulnerability that allows reflected cross-site scripting. This occurs due to inadequate input sanitization and output escaping through the bulk_action parameter. An attacker can exploit this weakness by tricking users into executing malicious scripts, potentially compromising their security when they interact with affected pages.
Affected Version(s)
Form Maker by 10Web β Mobile-Friendly Drag & Drop Contact Form Builder 0 <= 1.15.46