Impact
The Form Maker by 10Web – Mobile‑Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to reflected cross‑site scripting through its bulk_action parameter because input is not properly sanitized or escaped. An unauthenticated attacker can inject arbitrary JavaScript that will be executed in the victim’s browser when they follow a crafted link or trigger the action. This allows malicious code to run in the context of the website, potentially defacing pages or hijacking the victim’s session.
Affected Systems
Affected systems include WordPress sites that have the Form Maker by 10Web – Mobile‑Friendly Drag & Drop Contact Form Builder plugin from vendor 10web installed and activated, in all versions up to and including 1.15.46.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The vulnerability can be exploited remotely by an unauthenticated attacker with no special privileges. Although the EPSS score is not available and it is not listed in the KEV catalog, the exploitation path is simple—a crafted link containing a malicious bulk_action parameter. An attacker would send a victim such a link; when the victim visits the link, the injected script runs in their browser.
OpenCVE Enrichment