Description
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the bulk_action parameter in all versions up to, and including, 1.15.46 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Published: 2026-09-10
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Check for Update
AI Analysis

Impact

The Form Maker by 10Web – Mobile‑Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to reflected cross‑site scripting through its bulk_action parameter because input is not properly sanitized or escaped. An unauthenticated attacker can inject arbitrary JavaScript that will be executed in the victim’s browser when they follow a crafted link or trigger the action. This allows malicious code to run in the context of the website, potentially defacing pages or hijacking the victim’s session.

Affected Systems

Affected systems include WordPress sites that have the Form Maker by 10Web – Mobile‑Friendly Drag & Drop Contact Form Builder plugin from vendor 10web installed and activated, in all versions up to and including 1.15.46.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. The vulnerability can be exploited remotely by an unauthenticated attacker with no special privileges. Although the EPSS score is not available and it is not listed in the KEV catalog, the exploitation path is simple—a crafted link containing a malicious bulk_action parameter. An attacker would send a victim such a link; when the victim visits the link, the injected script runs in their browser.

Generated by OpenCVE AI on September 10, 2026 at 06:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the vendor's website or WordPress plugin repository for an updated version that addresses the bulk_action vulnerability.
  • As a temporary workaround, disable or remove the bulk_action functionality by adjusting plugin settings or editing the code to ignore the parameter.
  • If an update cannot be applied immediately, deactivate or uninstall the plugin from the WordPress site to prevent exploitation.

Generated by OpenCVE AI on September 10, 2026 at 06:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared 10web
10web form Maker By 10web – Mobile-friendly Drag & Drop Contact Form Builder
Wordpress
Wordpress wordpress
Vendors & Products 10web
10web form Maker By 10web – Mobile-friendly Drag & Drop Contact Form Builder
Wordpress
Wordpress wordpress

Thu, 10 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the bulk_action parameter in all versions up to, and including, 1.15.46 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Title Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.46 - Reflected Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

10web Form Maker By 10web – Mobile-friendly Drag & Drop Contact Form Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-11T20:19:13.726Z

Reserved: 2026-09-04T12:54:52.456Z

Link: CVE-2026-85645

cve-icon Vulnrichment

Updated: 2026-09-11T20:13:33.395Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T06:17:06.607

Modified: 2026-09-11T21:17:32.420

Link: CVE-2026-85645

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T08:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')