Impact
The Form Maker by 10Web WordPress plugin fails to properly parameterize a user-controlled value that is substituted into a dynamic SQL query for a database-backed choice field. This flaw enables subscriber‑level users to conduct a second‑order SQL injection that can compromise the confidentiality, integrity, and availability of the WordPress database. The weakness falls under the category of SQL injection (CWE‑89).
Affected Systems
The vulnerability is present in any installation of the Form Maker by 10Web plugin running a version earlier than 1.15.45. All WordPress sites that have this plugin in use and allow subscriber‑level users to interact with the affected form are impacted. The product is identified as Unknown:Form Maker by 10Web.
Risk and Exploitability
The flaw can be exploited by users with the subscriber role, provided they can enter data that is later stored and used in a dynamic query. Because the attack is second‑order, an initial injection may not have immediate effects until the stored data is subsequently processed. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, so the current exploitation probability is unknown. Nevertheless, the potential impact is high, and the absence of a CVSS score notwithstanding the severity is substantial.
OpenCVE Enrichment