Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.46 - Unauthenticated Stored Cross-Site Scripting
high
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.46. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a...
- CVSS:
- 7.2
- Affected:
- up to 1.15.46
- Fix:
- No patched version reported
- Disclosed:
- Aug 19, 2026
CVE-2026-66616 on NVD →
Form Maker by 10Web <= 1.15.44 - Authenticated (Subscriber+) SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause
medium
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause in all versions up to, and including, 1.15.44 due to insufficient escaping on the user supplied parameter and lack of suf...
- CVSS:
- 5.3
- Affected:
- up to 1.15.44
- Fixed in:
- 1.15.45
- Disclosed:
- Aug 14, 2026
CVE-2026-15993 on NVD →
Form Maker by 10Web <= 1.15.44 - Authenticated (Subscriber+) SQL Injection
medium
The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.15.44 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access...
- CVSS:
- 6.5
- Affected:
- up to 1.15.44
- Fixed in:
- 1.15.45
- Disclosed:
- Aug 10, 2026
CVE-2026-16977 on NVD →
Form Maker by 10Web <= 1.15.43 - Authenticated (Adminsitrator+) SQL Injection via 'groupids' Parameter
medium
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'groupids' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing...
- CVSS:
- 4.9
- Affected:
- up to 1.15.43
- Fixed in:
- 1.15.44
- Disclosed:
- Jun 17, 2026
CVE-2026-11776 on NVD →
Form Maker by 10Web <= 1.15.43 - Authenticated (Administrator+) SQL Injection via 'name' Parameter
medium
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'name' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL...
- CVSS:
- 4.9
- Affected:
- up to 1.15.43
- Fixed in:
- 1.15.44
- Disclosed:
- Jun 17, 2026
CVE-2026-11777 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.42 - Unauthenticated SQL Injection via 'inputs'
high
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection via the 'inputs' parameter in versions up to, and including, 1.15.42 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Th...
- CVSS:
- 7.5
- Affected:
- up to 1.15.42
- Fixed in:
- 1.15.43
- Disclosed:
- May 4, 2026
CVE-2026-3359 on NVD →
Form Maker by 10Web <= 1.15.40 - Authenticated (Administrator+) SQL Injection via 'ip_search' Parameter
medium
The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate', 'username_search', and 'useremail_search' parameters in all versions up to, and including, 1.15.40. This is due to the `WDW_FM_Library::validate_data()` method calling `stripslashes()` on user input...
- CVSS:
- 4.9
- Affected:
- up to 1.15.40
- Fixed in:
- 1.15.41
- Disclosed:
- Apr 16, 2026
CVE-2026-3330 on NVD →
Form Maker by 10Web <= 1.15.40 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Text Box
high
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box input type) in form submissions in all versions up to, and including, 1.15.40. This is due to insufficient input sanitization (`sanitize_text_field` strips tags but not quotes) and missing output esc...
- CVSS:
- 7.2
- Affected:
- up to 1.15.40
- Fixed in:
- 1.15.41
- Disclosed:
- Apr 13, 2026
CVE-2026-4388 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.38 - Unauthenticated SQL Injection
high
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.15.38 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for un...
- CVSS:
- 7.5
- Affected:
- up to 1.15.38
- Fixed in:
- 1.15.39
- Disclosed:
- Apr 8, 2026
CVE-2026-39502 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder < 1.15.38 - Unauthenticated SQL Injection
high
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to 1.15.38 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated at...
- CVSS:
- 7.5
- Affected:
- up to 1.15.38
- Fixed in:
- 1.15.38
- Disclosed:
- Mar 23, 2026
CVE-2025-15441 on NVD →
Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via Hidden Field
high
The Form Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via hidden field values in all versions up to, and including, 1.15.35. This is due to insufficient output escaping when displaying hidden field values in the admin submissions list. The plugin uses html_entity_decode() on user-supplied hid...
- CVSS:
- 7.1
- Affected:
- up to 1.15.35
- Fixed in:
- 1.15.36
- Disclosed:
- Feb 2, 2026
CVE-2026-1058 on NVD →
Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via SVG file
high
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.35. This is due to the plugin's default file upload allowlist including SVG files combined with weak substring-based extension validation. This makes it possible for unauthenticated attac...
- CVSS:
- 7.2
- Affected:
- up to 1.15.35
- Fixed in:
- 1.15.36
- Disclosed:
- Feb 2, 2026
CVE-2026-1065 on NVD →
Form Maker by 10Web <= 1.15.33 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.15.33 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts i...
- CVSS:
- 4.4
- Affected:
- up to 1.15.33
- Fixed in:
- 1.15.34
- Disclosed:
- May 19, 2025
CVE-2025-48341 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] <= 1.15.33 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Maker by 10Web allows Stored XSS. This issue affects Form Maker by 10Web: from n/a through 1.15.33.
- Affected:
- up to 1.15.33
- Fix:
- No patched version reported
- Disclosed:
- May 19, 2025
CVE-2025-48341 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.33
unknown
[en] The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 1.15.33
- Fixed in:
- 1.15.33
- Disclosed:
- May 15, 2025
CVE-2024-13053 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.32
unknown
[en] The Form Maker by 10Web WordPress plugin before 1.15.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 1.15.32
- Fixed in:
- 1.15.32
- Disclosed:
- Apr 16, 2025
CVE-2024-10680 on NVD →
Form Maker by 10Web <= 1.15.31 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...
- CVSS:
- 5.5
- Affected:
- up to 1.15.31
- Fixed in:
- 1.15.32
- Disclosed:
- Mar 26, 2025
CVE-2024-10680 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.30
unknown
[en] The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 1.15.30
- Fixed in:
- 1.15.30
- Disclosed:
- Mar 25, 2025
CVE-2024-10560 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.30
unknown
[en] The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 1.15.30
- Fixed in:
- 1.15.30
- Disclosed:
- Mar 24, 2025
CVE-2024-10558 on NVD →
Form Maker by 10Web <= 1.15.29 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.29 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...
- CVSS:
- 4.4
- Affected:
- up to 1.15.29
- Fixed in:
- 1.15.30
- Disclosed:
- Mar 3, 2025
CVE-2024-10560 on NVD →
Form Maker by 10Web <= 1.15.29 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.29 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...
- CVSS:
- 4.4
- Affected:
- up to 1.15.29
- Fixed in:
- 1.15.30
- Disclosed:
- Mar 2, 2025
CVE-2024-10558 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.33
unknown
[en] The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 1.15.33
- Fixed in:
- 1.15.33
- Disclosed:
- Feb 24, 2025
CVE-2024-13605 on NVD →
Form Maker by 10Web <= 1.15.32 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...
- CVSS:
- 4.4
- Affected:
- up to 1.15.32
- Fixed in:
- 1.15.33
- Disclosed:
- Feb 7, 2025
CVE-2024-13053 on NVD →
Form Maker by 10Web <= 1.15.32 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...
- CVSS:
- 4.4
- Affected:
- up to 1.15.32
- Fixed in:
- 1.15.33
- Disclosed:
- Feb 3, 2025
CVE-2024-13605 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.31
unknown
[en] The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 1.15.31
- Fixed in:
- 1.15.31
- Disclosed:
- Jan 7, 2025
CVE-2024-10562 on NVD →
Form Maker by 10Web <= 1.15.30 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...
- CVSS:
- 4.4
- Affected:
- up to 1.15.30
- Fixed in:
- 1.15.31
- Disclosed:
- Dec 17, 2024
CVE-2024-10562 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.28
unknown
[en] Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,...
- Affected:
- up to 1.15.28
- Fixed in:
- 1.15.28
- Disclosed:
- Dec 4, 2024
CVE-2024-5020 on NVD →
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library
medium
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 1.15.27
- Fixed in:
- 1.15.28
- Disclosed:
- Dec 3, 2024
CVE-2024-5020 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.30 - Reflected Cross-Site Scripting via add_query_arg Parameter
medium
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.15.30. This makes it possible for unauthenticated attackers to i...
- CVSS:
- 6.1
- Affected:
- up to 1.15.30
- Fixed in:
- 1.15.31
- Disclosed:
- Nov 10, 2024
CVE-2024-10265 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.31
unknown
[en] The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.15.30. This makes it possible for unauthenticated attackers...
- Affected:
- up to 1.15.31
- Fixed in:
- 1.15.31
- Disclosed:
- Nov 10, 2024
CVE-2024-10265 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.28
unknown
[en] The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrat...
- Affected:
- up to 1.15.28
- Fixed in:
- 1.15.28
- Disclosed:
- Sep 26, 2024
CVE-2024-8633 on NVD →
Form Maker <= 1.15.27 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-le...
- CVSS:
- 5.5
- Affected:
- up to 1.15.27
- Fixed in:
- 1.15.28
- Disclosed:
- Sep 25, 2024
CVE-2024-8633 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.27
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Reflected XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.26.
- Affected:
- up to 1.15.27
- Fixed in:
- 1.15.27
- Disclosed:
- Aug 12, 2024
CVE-2024-43220 on NVD →
Form Maker by 10Web <= 1.15.26 - Reflected Cross-Site Scripting
medium
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.15.26 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra...
- CVSS:
- 6.1
- Affected:
- up to 1.15.26
- Fixed in:
- 1.15.27
- Disclosed:
- Aug 9, 2024
CVE-2024-43220 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.26
unknown
[en] The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 1.15.26
- Fixed in:
- 1.15.26
- Disclosed:
- Jul 1, 2024
CVE-2024-6130 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.25 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.25 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...
- CVSS:
- 4.4
- Affected:
- up to 1.15.25
- Fixed in:
- 1.15.26
- Disclosed:
- Jun 10, 2024
CVE-2024-6130 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.21
unknown
[en] Improper Restriction of Excessive Authentication Attempts vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Functionality Bypass.This issue affects Form Maker by 10Web: from n/a through 1.15.20.
- Affected:
- up to 1.15.21
- Fixed in:
- 1.15.21
- Disclosed:
- Jun 4, 2024
CVE-2023-48290 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.25
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.24.
- Affected:
- up to 1.15.25
- Fixed in:
- 1.15.25
- Disclosed:
- May 9, 2024
CVE-2024-34437 on NVD →
Form Maker by 10Web <= 1.15.24 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...
- CVSS:
- 4.4
- Affected:
- up to 1.15.24
- Fixed in:
- 1.15.25
- Disclosed:
- May 7, 2024
CVE-2024-34437 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.25
unknown
[en] The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name autofilled into forms in all versions up to, and including, 1.15.24 due to insufficient input sanitization and output escaping. This makes it possib...
- Affected:
- up to 1.15.25
- Fixed in:
- 1.15.25
- Disclosed:
- Apr 27, 2024
CVE-2024-2258 on NVD →
Form Maker by 10Web <= 1.15.24 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting
medium
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name autofilled into forms in all versions up to, and including, 1.15.24 due to insufficient input sanitization and output escaping. This makes it possible fo...
- CVSS:
- 4.4
- Affected:
- up to 1.15.24
- Fixed in:
- 1.15.25
- Disclosed:
- Apr 26, 2024
CVE-2024-2258 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.24
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.23.
- Affected:
- up to 1.15.24
- Fixed in:
- 1.15.24
- Disclosed:
- Apr 17, 2024
CVE-2024-32534 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.23 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.15.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to in...
- CVSS:
- 4.4
- Affected:
- up to 1.15.23
- Fixed in:
- 1.15.24
- Disclosed:
- Apr 15, 2024
CVE-2024-32534 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.23
unknown
[en] The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.15.22 via the signature functionality. This makes it possible for unauthenticated attackers to extract sensitive data including use...
- Affected:
- up to 1.15.23
- Fixed in:
- 1.15.23
- Disclosed:
- Apr 9, 2024
CVE-2024-2112 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 - Sensitive Information Exposure
medium
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.15.22 via the signature functionality. This makes it possible for unauthenticated attackers to extract sensitive data including user sig...
- CVSS:
- 5.9
- Affected:
- up to 1.15.22
- Fixed in:
- 1.15.23
- Disclosed:
- Mar 22, 2024
CVE-2024-2112 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.22
unknown
[en] The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.15.21. This is due to missing or incorrect nonce validation on the 'execute' function. This makes it possible for unauthenticated attac...
- Affected:
- up to 1.15.22
- Fixed in:
- 1.15.22
- Disclosed:
- Jan 27, 2024
CVE-2024-0667 on NVD →
Form-Maker (twb_form-maker) <= 1.15.21 - Cross-Site Request Forgery to Limited Code Execution via Execute
medium
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.15.21. This is due to missing or incorrect nonce validation on the 'execute' function. This makes it possible for unauthenticated attackers...
- CVSS:
- 5.4
- Affected:
- up to 1.15.21
- Fixed in:
- 1.15.22
- Disclosed:
- Jan 26, 2024
CVE-2024-0667 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.19
unknown
[en] Unauth. Stored Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin <= 1.15.18 versions.
- Affected:
- up to 1.15.19
- Fixed in:
- 1.15.19
- Disclosed:
- Oct 18, 2023
CVE-2023-45071 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.19
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin <= 1.15.18 versions.
- Affected:
- up to 1.15.19
- Fixed in:
- 1.15.19
- Disclosed:
- Oct 18, 2023
CVE-2023-45070 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.20
unknown
[en] The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE
- Affected:
- up to 1.15.20
- Fixed in:
- 1.15.20
- Disclosed:
- Oct 16, 2023
CVE-2023-4666 on NVD →
Form Maker <= 1.15.20 - Captcha Bypass
medium
The Form Maker plugin for WordPress is vulnerable to Captcha Bypass in versions up to, and including, 1.15.20 due to insufficient input verification. This makes it possible for unauthenticated attackers to automate form submissions.
- CVSS:
- 5.3
- Affected:
- up to 1.15.21
- Fixed in:
- 1.15.21
- Disclosed:
- Oct 11, 2023
CVE-2023-48290 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.21
unknown
The Form Maker plugin for WordPress is vulnerable to Captcha Bypass in versions up to, and including, 1.15.20 due to insufficient input verification. This makes it possible for unauthenticated attackers to automate form submissions.
- Affected:
- up to 1.15.21
- Fixed in:
- 1.15.21
- Disclosed:
- Oct 11, 2023
Form Maker by 10Web <= 1.15.18 - Unauthenticated Stored Cross-Site Scripting
high
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type_textarea' field of form submissions in versions up to, and including, 1.15.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...
- CVSS:
- 7.2
- Affected:
- up to 1.15.18
- Fixed in:
- 1.15.19
- Disclosed:
- Oct 3, 2023
CVE-2023-45071 on NVD →
Form Maker by 10Web <= 1.15.18 - Reflected Cross-Site Scripting
medium
The Form Maker by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a few parameters related to searching in versions up to, and including, 1.15.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...
- CVSS:
- 6.1
- Affected:
- up to 1.15.18
- Fixed in:
- 1.15.19
- Disclosed:
- Oct 3, 2023
CVE-2023-45070 on NVD →
Form Maker by 10Web <= 1.15.19 - Unauthenticated Arbitrary File Upload
critical
The Form Maker by 10Web plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'type_signature' case of the save_db() function in versions up to, and including, 1.5.19. This makes it possible for unauthenticated attackers to upload arbitrary files, via the signature...
- CVSS:
- 9.8
- Affected:
- up to 1.15.20
- Fixed in:
- 1.15.20
- Disclosed:
- Sep 7, 2023
CVE-2023-4666 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.20
unknown
The Form Maker by 10Web plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'type_signature' case of the save_db() function in versions up to, and including, 1.5.19. This makes it possible for unauthenticated attackers to upload arbitrary files, via the signature...
- Affected:
- up to 1.15.20
- Fixed in:
- 1.15.20
- Disclosed:
- Sep 7, 2023
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.20
unknown
Update the WordPress Form Maker by 10Web plugin to the latest available version (at least 1.15.20).
An unknown person discovered and reported this Arbitrary File Upload vulnerability in WordPress Form Maker by 10Web Plugin. This could allow a malicious actor to upload any type of file to your website. This can include...
- Affected:
- up to 1.15.20
- Fixed in:
- 1.15.20
- Disclosed:
- Sep 7, 2023
Form Maker <= 1.15.16 - Missing Authorization in check_score
medium
The Form Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_score function in versions up to, and including, 1.15.16. This makes it possible for authenticated attackers, with subscriber-level privileges and above, to reveal the score of posts.
- CVSS:
- 4.3
- Affected:
- up to 1.15.16
- Fixed in:
- 1.15.17
- Disclosed:
- Jun 14, 2023
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.17
unknown
The Form Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_score function in versions up to, and including, 1.15.16. This makes it possible for authenticated attackers, with subscriber-level privileges and above, to reveal the score of posts.
- Affected:
- up to 1.15.17
- Fixed in:
- 1.15.17
- Disclosed:
- Jun 14, 2023
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.15.6
unknown
[en] The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
- Affected:
- up to 1.15.6
- Fixed in:
- 1.15.6
- Disclosed:
- Oct 25, 2022
CVE-2022-3300 on NVD →
Form Maker <= 1.15.5 - Authenticated (Administrator+) SQL Injection
high
The Form Maker plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in versions up to, and including, 1.15.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administra...
- CVSS:
- 7.2
- Affected:
- up to 1.15.5
- Fixed in:
- 1.15.6
- Disclosed:
- Sep 29, 2022
CVE-2022-3300 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.14.12
unknown
[en] The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which could allow high privilege user such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
- Affected:
- up to 1.14.12
- Fixed in:
- 1.14.12
- Disclosed:
- May 30, 2022
CVE-2022-1564 on NVD →
Form Maker <= 1.14.11 - Stored Cross-Site Scripting
medium
The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which could allow high privilege user such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
- CVSS:
- 5.5
- Affected:
- up to 1.14.11
- Fixed in:
- 1.14.12
- Disclosed:
- May 9, 2022
CVE-2022-1564 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.13.60
unknown
[en] The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue
- Affected:
- up to 1.13.60
- Fixed in:
- 1.13.60
- Disclosed:
- Aug 16, 2021
CVE-2021-24526 on NVD →
Form Maker <= 1.13.59 - Authenticated Stored Cross-Site Scripting
medium
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue
- CVSS:
- 5.4
- Affected:
- up to 1.13.59
- Fixed in:
- 1.13.60
- Disclosed:
- Jul 15, 2021
CVE-2021-24526 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.13.57
unknown
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze and Thura Moe Myint in WordPress Form Maker by 10Web plugin (versions <= 1.13.56).
- Affected:
- up to 1.13.57
- Fixed in:
- 1.13.57
- Disclosed:
- May 19, 2021
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.13.57
unknown
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by m0ze and Thura Moe Myint in WordPress Form Maker by 10Web plugin (versions <= 1.13.56).
- Affected:
- up to 1.13.57
- Fixed in:
- 1.13.57
- Disclosed:
- May 19, 2021
Form Maker by 10Web < 1.13.40 - Reflected Cross-Site Scripting
medium
The Form Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.13.39 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tr...
- CVSS:
- 6.1
- Affected:
- up to 1.13.40
- Fixed in:
- 1.13.40
- Disclosed:
- Jul 12, 2020
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.13.40
unknown
The Form Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.13.39 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tr...
- Affected:
- up to 1.13.40
- Fixed in:
- 1.13.40
- Disclosed:
- Jul 12, 2020
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.13.40
unknown
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by Andy Tyler in WordPress Form Maker by 10Web plugin (versions <= 1.13.39).
- Affected:
- up to 1.13.40
- Fixed in:
- 1.13.40
- Disclosed:
- Jul 12, 2020
Form Maker by 10Web <= 1.13.35 - SQL Injection
high
The Form Maker plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in versions up to, and including, 1.13.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to appe...
- CVSS:
- 7.2
- Affected:
- up to 1.13.35
- Fixed in:
- 1.13.36
- Disclosed:
- May 26, 2020
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.13.36
unknown
Authenticated SQL Injection (SQLi) vulnerability discovered by Vu Tien Hoa in WordPress Form Maker by 10Web plugin (versions <= 1.13.35).
- Affected:
- up to 1.13.36
- Fixed in:
- 1.13.36
- Disclosed:
- May 26, 2020
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.13.36
unknown
The Form Maker plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in versions up to, and including, 1.13.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to appe...
- Affected:
- up to 1.13.36
- Fixed in:
- 1.13.36
- Disclosed:
- May 26, 2020
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.13.3
unknown
[en] In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.
- Affected:
- up to 1.13.3
- Fixed in:
- 1.13.3
- Disclosed:
- May 23, 2019
CVE-2019-10866 on NVD →
Form Maker by 10Web <= 1.13.2 - Authenticated SQL Injection
high
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.
- CVSS:
- 8.8
- Affected:
- up to 1.13.3
- Fixed in:
- 1.13.3
- Disclosed:
- May 10, 2019
CVE-2019-10866 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.13.5
unknown
[en] The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.
- Affected:
- up to 1.13.5
- Fixed in:
- 1.13.5
- Disclosed:
- Apr 29, 2019
CVE-2019-11590 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.13.5
unknown
Cross-Site Request Forgery (CSRF) vulnerability found by Panagiotis Vagenas in WordPress Form Maker by 10Web plugin (versions <= 1.13.4).
- Affected:
- up to 1.13.5
- Fixed in:
- 1.13.5
- Disclosed:
- Apr 10, 2019
Form Maker by 10Web <= 1.13.4 - Cross-Site Request Forgery to Local File Inclusion
high
The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.
- CVSS:
- 8.1
- Affected:
- up to 1.13.4
- Fixed in:
- 1.13.5
- Disclosed:
- Apr 5, 2019
CVE-2019-11590 on NVD →
Form Maker by 10Web <= 1.12.21 - CSV Injection
high
The WebDorado "Form Maker by WD" plugin before 1.12.22 for WordPress allows CSV injection.
- CVSS:
- 7.8
- Affected:
- up to 1.12.22
- Fixed in:
- 1.12.22
- Disclosed:
- Apr 27, 2018
CVE-2018-10504 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.12.24
unknown
[en] The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
- Affected:
- up to 1.12.24
- Fixed in:
- 1.12.24
- Disclosed:
- Apr 27, 2018
CVE-2018-10504 on NVD →
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.6.6
unknown
This plugin is prone to a cross site scripting vulnerability in front_end_form_maker.php.
Update the plugin.
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.6
- Disclosed:
- Aug 1, 2014
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.13.40
unknown
The 'Form Maker by 10Web' WordPress plugin is vulnerable to XSS in the 'blocked_ips_fm' page. A logged-in site administrator who follows a crafted link will trigger arbitrary JavaScript code to be run in their browser in the context of their privileged account on the WordPress site.
- Affected:
- up to 1.13.40
- Fixed in:
- 1.13.40
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.13.36
unknown
Authenticated (admin+) SQL injection in the Form Maker by 10Web WordPress Plugin 1.13.35 exists via the /wordpress/wp-admin/admin.php?page=blocked_ips_fm&s=1" s parameter.
Edit (WPScanTeam):
- Initial reported version (5.4.1) does not exist, confirmed to be 1.13.35 by researcher
- May 25th, 2020 - details...
- Affected:
- up to 1.13.36
- Fixed in:
- 1.13.36
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder [form-maker] < 1.6.6
unknown
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin was affected by a front_end_form_maker.php Unspecified XSS security vulnerability.
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.6