Impact
The Form Maker by 10Web WordPress plugin does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query for a database‑backed choice field. Consequently, subscriber‑level users can perform second‑order SQL injection by entering crafted data that later becomes part of an SQL statement. This flaw is classified as a SQL injection vulnerability (CWE‑89).
Affected Systems
The vulnerability is present in any installation of the Form Maker by 10Web plugin running a version earlier than 1.15.45. All WordPress sites that have this plugin in use and allow subscriber‑level users to interact with the affected form are impacted. The product is identified as Unknown:Form Maker by 10Web.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, but the EPSS score of <1% suggests a low probability that this vulnerability will be actively exploited. The lack of listing in the CISA KEV catalog indicates no documented exploitation. The likely attack path requires a subscriber‑level user to submit data that is later stored and used in a dynamic query; the second‑order nature means the impact may only materialize when the stored data is processed. Based on the EPSS score, the exploitation risk is considered low, but the high severity remains a concern.
OpenCVE Enrichment