Impact
The vulnerability allows an unauthenticated attacker to inject malicious JavaScript into web pages rendered by the Form Maker by 10Web plugin, potentially enabling the attacker to hijack user sessions, deface the site, or steal credentials. This flaw is a classic input validation issue classified as CWE‑79, where user‑supplied data is reflected without proper sanitization.
Affected Systems
The issue affects the WordPress plugin 10Web: Form Maker by 10Web, specifically all releases up to and including version 1.15.46. Users running any of these versions are potential victims.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level. Because the vulnerability is unauthenticated, any visitor to a site that allows form submissions can potentially trigger the XSS. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalogue. Attackers can exploit the flaw by submitting crafted input through exposed form fields or by manipulating URL parameters that are reflected in the page output.
OpenCVE Enrichment