Description
The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection.
Published: 2026-08-12
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Form Maker by 10Web WordPress plugin fails to properly parameterize a user-controlled value that is substituted into a dynamic SQL query for a database-backed choice field. This flaw enables subscriber‑level users to conduct a second‑order SQL injection that can compromise the confidentiality, integrity, and availability of the WordPress database. The weakness falls under the category of SQL injection (CWE‑89).

Affected Systems

The vulnerability is present in any installation of the Form Maker by 10Web plugin running a version earlier than 1.15.45. All WordPress sites that have this plugin in use and allow subscriber‑level users to interact with the affected form are impacted. The product is identified as Unknown:Form Maker by 10Web.

Risk and Exploitability

The flaw can be exploited by users with the subscriber role, provided they can enter data that is later stored and used in a dynamic query. Because the attack is second‑order, an initial injection may not have immediate effects until the stored data is subsequently processed. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, so the current exploitation probability is unknown. Nevertheless, the potential impact is high, and the absence of a CVSS score notwithstanding the severity is substantial.

Generated by OpenCVE AI on August 12, 2026 at 12:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official update to Form Maker by 10Web version 1.15.45 or later.
  • If the update cannot be applied immediately, restrict subscriber‑level users from accessing the form field that triggers the dynamic query or remove that field from the form.
  • Disable or remove the Form Maker by 10Web plugin entirely until the security fix is applied.
  • Validate all user input when rendering dynamic SQL queries in custom WordPress plugins to prevent future injection vulnerabilities.

Generated by OpenCVE AI on August 12, 2026 at 12:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE‑89

Wed, 12 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection.
Title Form Maker by 10Web < 1.15.45 - Subscriber+ SQL Injection via display_name
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-12T06:00:15.954Z

Reserved: 2026-07-24T08:34:07.336Z

Link: CVE-2026-16977

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-12T06:19:18.193

Modified: 2026-08-12T06:19:18.193

Link: CVE-2026-16977

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T12:30:03Z

Weaknesses