Impact
The plugin’s map longitude/latitude fields are stored without proper input sanitization or output escaping, allowing an unauthenticated attacker to embed arbitrary JavaScript. When another site visitor accesses a page that displays the stored data, the injected script runs in the victim’s browser, potentially stealing session cookies, defacing content, or redirecting users to malicious sites. This is a classic stored cross‑site scripting weakness (CWE‑79).
Affected Systems
WordPress sites that have the Form Maker by 10Web – Mobile‑Friendly Drag & Drop Contact Form Builder plugin installed in any version up to and including 1.15.47 are affected. The vulnerability exists regardless of the host WordPress installation version or other plugins. Any site that accepts user submissions through the map fields is at risk.
Risk and Exploitability
With a CVSS score of 7.2 this vulnerability is considered high severity. The attack is unauthenticated and only requires an active web request that creates a stored entry; no privileged access or complex setup is necessary. Although no exploit is currently tracked in the CISA KEV catalog and EPSS data is unavailable, the ubiquity of WordPress and the simplicity of the exploit path make it plausible that attackers could target affected sites. Immediate attention is recommended to prevent potential exploitation.
OpenCVE Enrichment