Impact
A flaw in the Form Maker by 10Web plugin allows SQL injection when a subscriber submits a form. The injected payload can be used to execute arbitrary SQL commands against the WordPress database, which can lead to disclosure, alteration, or deletion of data. The vulnerability is a classic type of injection weakness (CWE‑89) and can compromise the confidentiality and integrity of the application’s data. It does not directly provide code execution on the server, but compromised database access effectively gives an attacker control over sensitive information and potential administrative actions.
Affected Systems
The vulnerability affects the WordPress Form Maker by 10Web plugin version 1.15.44 and all earlier releases. Users who have installed any of these versions on their WordPress sites are exposed. The plugin is distributed solely by 10Web and is a third‑party component within the WordPress ecosystem.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity condition. No EPSS score is available, so the exploitation probability cannot be quantified from this data. The vulnerability is not listed in CISA’s KEV catalog at this time. Attackers can exploit the weakness by submitting malicious input through any exposed form, implying the attack vector is via the web interface and does not require privileged credentials.
OpenCVE Enrichment