Impact
The Form Maker by 10Web plugin for WordPress is vulnerable to reflected cross‑site scripting through the 'inputs' array key. Because the plugin does not properly sanitize or escape user input, an unauthenticated attacker can inject arbitrary JavaScript that will run in a victim’s browser when the victim visits a crafted URL. This flaw could allow attackers to steal credentials, deface sites, or perform other malicious actions within the victim’s session.
Affected Systems
WordPress sites that use the 10Web Form Maker plugin, specifically any installation running version 1.15.48 or older. The vulnerability exists in all releases up to and including 1.15.48.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity, and the vulnerability is not listed in the CISA KEV catalog. While no EPSS data is available, the flaw can be exploited through a simple crafted link that a victim may click on or receive via email, leading to potential session hijacking or data theft. The attack vector is remote and does not require authentication, making it attractive to malicious actors.
OpenCVE Enrichment