Description
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Published: 2026-08-13
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Form Maker by 10Web plugin allows SQL injection when a subscriber submits a form. The injected payload can be used to execute arbitrary SQL commands against the WordPress database, which can lead to disclosure, alteration, or deletion of data. The vulnerability is a classic type of injection weakness (CWE‑89) and can compromise the confidentiality and integrity of the application’s data. It does not directly provide code execution on the server, but compromised database access effectively gives an attacker control over sensitive information and potential administrative actions.

Affected Systems

The vulnerability affects the WordPress Form Maker by 10Web plugin version 1.15.44 and all earlier releases. Users who have installed any of these versions on their WordPress sites are exposed. The plugin is distributed solely by 10Web and is a third‑party component within the WordPress ecosystem.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity condition. No EPSS score is available, so the exploitation probability cannot be quantified from this data. The vulnerability is not listed in CISA’s KEV catalog at this time. Attackers can exploit the weakness by submitting malicious input through any exposed form, implying the attack vector is via the web interface and does not require privileged credentials.

Generated by OpenCVE AI on August 13, 2026 at 15:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WordPress Form Maker by 10Web plugin to version 1.15.45 or later
  • If an update is not immediately possible, remove or disable the plugin from the site
  • Sanitize and validate all form inputs on the server side to prevent injection strings

Generated by OpenCVE AI on August 13, 2026 at 15:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References

No reference.

History

Sat, 15 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title WordPress Form Maker by 10Web plugin <= 1.15.44 - SQL Injection vulnerability
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 15 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title WordPress Form Maker by 10Web plugin <= 1.15.44 - SQL Injection vulnerability
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Title WordPress Form Maker by 10Web plugin <= 1.15.44 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Description Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44 versions. This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Thu, 13 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared 10web
10web form Maker By 10web
Wordpress
Wordpress wordpress
Vendors & Products 10web
10web form Maker By 10web
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44 versions.
Title WordPress Form Maker by 10Web plugin <= 1.15.44 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

10web Form Maker By 10web
Wordpress Wordpress
cve-icon MITRE

Status: REJECTED

Assigner: Patchstack

Published:

Updated: 2026-08-14T07:30:45.332Z

Reserved: 2026-02-25T12:14:47.650Z

Link: CVE-2026-28184

cve-icon Vulnrichment

Updated:

cve-icon NVD

Status : Rejected

Published: 2026-08-13T14:17:00.100

Modified: 2026-08-14T08:17:38.583

Link: CVE-2026-28184

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:45:04Z

Weaknesses

No weakness.