WordPress Plugin Vulnerabilities

Form Maker by 10Web < 1.15.45 - Subscriber+ SQL Injection via display_name

Description

The plugin does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection.

Proof of Concept

Affects Plugins

Fixed in 1.15.45

References

Classification

Type
SQLI
OWASP top 10
CWE
CVSS

Miscellaneous

Original Researcher
Revanth Meesala
Submitter
Revanth Meesala
Verified
Yes

Timeline

Publicly Published
2026-08-10 (about 2 days ago)
Added
2026-08-10 (about 1 day ago)
Last Updated
2026-08-11 (about 9 hours ago)

Other