Impact
Improper neutralization of input during web page generation in the 10Web Form Maker plugin introduces a stored cross‑site scripting vulnerability. An unauthenticated attacker can inject malicious JavaScript into pages generated by the plugin, enabling session hijacking, site defacement, or credential theft. This flaw is a classic input validation issue classified as CWE‑79, where user‑supplied data is reflected without proper sanitization.
Affected Systems
The issue affects the WordPress plugin 10Web: Form Maker by 10Web, specifically all releases up to and including version 1.15.48. Users running any of these versions are potential victims.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level. Because the vulnerability is unauthenticated, any visitor to a site that allows form submissions can potentially trigger the XSS. The EPSS score is < 1%, suggesting a low but nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalogue. Attackers can exploit the flaw by submitting crafted input through exposed form fields or by manipulating URL parameters that are reflected in the page output.
OpenCVE Enrichment