cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forform-maker form-maker

Direction: ascending
Jun 06, 2024

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder # CVE-2022-1564

CVE, Research URL

CVE-2022-1564

Date
May 30, 2022
Research Description
The Form Maker by 10Web WordPress plugin before 1.14.12 does not sanitize and escape the Custom Text settings, which could allow high privilege user such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Affected versions
max 1.14.12.
Status
vulnerable

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder # CVE-2022-3300

CVE, Research URL

CVE-2022-3300

Date
Oct 25, 2022
Research Description
The Form Maker by 10Web WordPress plugin before 1.15.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
Affected versions
max 1.15.6.
Status
vulnerable

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder # CVE-2021-24526

CVE, Research URL

CVE-2021-24526

Date
Aug 16, 2021
Research Description
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not escape its Form Title before outputting it in an attribute when editing a form in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue
Affected versions
max 1.13.60.
Status
vulnerable

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder # CVE-2019-11590

CVE, Research URL

CVE-2019-11590

Date
Apr 29, 2019
Research Description
The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.
Affected versions
max 1.13.5.
Status
vulnerable

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder # CVE-2018-10504

CVE, Research URL

CVE-2018-10504

Date
Apr 27, 2018
Research Description
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
Affected versions
max 1.12.24.
Status
vulnerable

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder # CVE-2019-10866

CVE, Research URL

CVE-2019-10866

Date
May 24, 2019
Research Description
In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_parameters in the file form-maker/admin/models/Submissions_fm.php with a crafted value of the /models/Submissioc parameter.
Affected versions
max 1.13.3.
Status
vulnerable

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder # CVE-2024-32534

CVE, Research URL

CVE-2024-32534

Date
Apr 17, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.23.
Affected versions
max 1.15.24.
Status
vulnerable

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder # CVE-2023-45071

CVE, Research URL

CVE-2023-45071

Date
Oct 18, 2023
Research Description
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin <= 1.15.18 versions.
Affected versions
max 1.15.19.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2023-48290

CVE, Research URL

CVE-2023-48290

Date
Jun 04, 2024
Research Description
Improper Restriction of Excessive Authentication Attempts vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Functionality Bypass.This issue affects Form Maker by 10Web: from n/a through 1.15.20.
Affected versions
max 1.15.21.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2024-2112

CVE, Research URL

CVE-2024-2112

Date
Apr 10, 2024
Research Description
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.15.22 via the signature functionality. This makes it possible for unauthenticated attackers to extract sensitive data including user signatures.
Affected versions
max 1.15.23.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2024-0667

CVE, Research URL

CVE-2024-0667

Date
Jan 27, 2024
Research Description
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.15.21. This is due to missing or incorrect nonce validation on the 'execute' function. This makes it possible for unauthenticated attackers to execute arbitrary methods in the 'BoosterController' class via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 1.15.22.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2024-2258

CVE, Research URL

CVE-2024-2258

Date
Apr 27, 2024
Research Description
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's display name autofilled into forms in all versions up to, and including, 1.15.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.15.25.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2023-45070

CVE, Research URL

CVE-2023-45070

Date
Oct 18, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin <= 1.15.18 versions.
Affected versions
max 1.15.19.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2023-4666

CVE, Research URL

CVE-2023-4666

Date
Oct 17, 2023
Research Description
The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE
Affected versions
max 1.15.20.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2024-34437

CVE, Research URL

CVE-2024-34437

Date
May 14, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.24.
Affected versions
max 1.15.25.
Status
vulnerable
Jul 02, 2024

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2024-6130

CVE, Research URL

CVE-2024-6130

Date
Jul 01, 2024
Research Description
The Form Maker by 10Web WordPress plugin before 1.15.26 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
max 1.15.26.
Status
vulnerable
Aug 13, 2024

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2024-43220

CVE, Research URL

CVE-2024-43220

Date
Aug 13, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Reflected XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.26.
Affected versions
max 1.15.27.
Status
vulnerable
Sep 28, 2024

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2024-8633

CVE, Research URL

CVE-2024-8633

Date
Sep 26, 2024
Research Description
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.15.28.
Status
vulnerable
Nov 10, 2024

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2024-10265

CVE, Research URL

CVE-2024-10265

Date
Nov 10, 2024
Research Description
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.15.30. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 1.15.31.
Status
vulnerable
Dec 06, 2024

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2024-5020

CVE, Research URL

CVE-2024-5020

Date
Dec 04, 2024
Research Description
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.15.28.
Status
vulnerable
Jan 10, 2025

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2024-10562

CVE, Research URL

CVE-2024-10562

Date
Jan 07, 2025
Research Description
The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 1.15.31.
Status
vulnerable
Feb 26, 2025

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2024-13605

CVE, Research URL

CVE-2024-13605

Date
Feb 24, 2025
Research Description
The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 1.15.33.
Status
vulnerable
Mar 26, 2025

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2024-10558

CVE, Research URL

CVE-2024-10558

Date
Mar 24, 2025
Research Description
The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 1.15.30.
Status
vulnerable
Apr 18, 2025

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2024-10680

CVE, Research URL

CVE-2024-10680

Date
Apr 16, 2025
Research Description
The Form Maker by 10Web WordPress plugin before 1.15.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 1.15.32.
Status
vulnerable
May 06, 2025

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2024-10560

CVE, Research URL

CVE-2024-10560

Date
Mar 25, 2025
Research Description
The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 1.15.30.
Status
vulnerable
May 17, 2025

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2024-13053

CVE, Research URL

CVE-2024-13053

Date
May 16, 2025
Research Description
The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 1.15.33.
Status
vulnerable
May 21, 2025

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2025-48341

CVE, Research URL

CVE-2025-48341

Date
May 19, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Maker by 10Web form-maker allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through <= 1.15.33.
Affected versions
max 1.15.34.
Status
vulnerable
Apr 15, 2026

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2025-15441

CVE, Research URL

CVE-2025-15441

Date
Apr 13, 2026
Research Description
The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which could make SQL Injection attacks possible in certain contexts.
Affected versions
max 1.15.38.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2026-1058

CVE, Research URL

CVE-2026-1058

Date
Feb 03, 2026
Research Description
The Form Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via hidden field values in all versions up to, and including, 1.15.35. This is due to insufficient output escaping when displaying hidden field values in the admin submissions list. The plugin uses html_entity_decode() on user-supplied hidden field values without subsequent escaping before output, which converts HTML entity-encoded payloads back into executable JavaScript. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in the admin submissions view that will execute whenever an administrator accesses the submissions list.
Affected versions
max 1.15.36.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2026-39502

CVE, Research URL

CVE-2026-39502

Date
Jun 16, 2026
Research Description
Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.
Affected versions
max 1.15.39.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2026-4388

CVE, Research URL

CVE-2026-4388

Date
Apr 14, 2026
Research Description
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box input type) in form submissions in all versions up to, and including, 1.15.40. This is due to insufficient input sanitization (`sanitize_text_field` strips tags but not quotes) and missing output escaping when rendering submission data in the admin Submissions view. This makes it possible for unauthenticated attackers to inject arbitrary JavaScript through a form submission that executes in the browser of an administrator who views the submission details.
Affected versions
max 1.15.41.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2026-1065

CVE, Research URL

CVE-2026-1065

Date
Feb 03, 2026
Research Description
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.35. This is due to the plugin's default file upload allowlist including SVG files combined with weak substring-based extension validation. This makes it possible for unauthenticated attackers to upload malicious SVG files containing JavaScript code that will execute when viewed by administrators or site visitors via file upload fields in forms granted they can submit forms.
Affected versions
max 1.15.36.
Status
vulnerable
Apr 20, 2026

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2026-3330

CVE, Research URL

CVE-2026-3330

Date
Apr 17, 2026
Research Description
The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate', 'username_search', and 'useremail_search' parameters in all versions up to, and including, 1.15.40. This is due to the `WDW_FM_Library::validate_data()` method calling `stripslashes()` on user input (removing WordPress's `wp_magic_quotes()` protection) and the `FMModelSubmissions_fm::get_labels_parameters()` function directly concatenating user-supplied values into SQL queries without using `$wpdb->prepare()`. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Additionally, the Submissions controller skips nonce verification for the `display` task, which means this vulnerability can be triggered via CSRF by tricking an administrator into clicking a crafted link.
Affected versions
max 1.15.41.
Status
vulnerable
May 06, 2026

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2026-3359

CVE, Research URL

CVE-2026-3359

Date
May 05, 2026
Research Description
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection via the 'inputs' parameter in versions up to, and including, 1.15.42 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
max 1.15.43.
Status
vulnerable
May 26, 2026

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2018-25346

CVE, Research URL

CVE-2018-25346

Date
May 24, 2026
Research Description
WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through the FormMakerSQLMapping and generete_csv actions. Attackers can submit POST requests with malicious SQL payloads in the name and search_labels parameters to extract, modify, or escalate privileges within the WordPress database.
Affected versions
max 1.12.24.
Status
vulnerable
Jun 16, 2026

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # 01fa8e513d9dd8b4e66ea53b7d903be4d2b96ff4

Date
May 19, 2021
Research Description
Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.13.57 WordPress Form Maker by 10Web plugin <= 1.13.56 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered by m0ze and Thura Moe Myint in WordPress Form Maker by 10Web plugin (versions <= 1.13.56).
Affected versions
max 1.13.57.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # e5a1de5725772c4d93564beeb614b58b72ba515a

Date
Aug 01, 2014
Research Description
Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.6.6 WordPress Form Maker Plugin <= 1.6.4 - Unspecified Cross Site Scripting This plugin is prone to a cross site scripting vulnerability in front_end_form_maker.php. Update the plugin.
Affected versions
max 1.6.6.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # 3c75c7b2f76e434fc709f6e73f77754e906a17e5

Date
Jul 12, 2020
Research Description
Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.13.40 Form Maker by 10Web < 1.13.40 - Reflected Cross-Site Scripting The Form Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.13.39 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 1.13.40.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # 6915212aa945894d15599f8cba927c82020049a6

Date
May 26, 2020
Research Description
Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.13.36 Form Maker by 10Web <= 1.13.35 - SQL Injection The Form Maker plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in versions up to, and including, 1.13.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
max 1.13.36.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # 1c1ce219d063c0f054aedd2d97d1e4eae4793edf

Date
May 19, 2021
Research Description
Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.13.57 WordPress Form Maker by 10Web plugin <= 1.13.56 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by m0ze and Thura Moe Myint in WordPress Form Maker by 10Web plugin (versions <= 1.13.56).
Affected versions
max 1.13.57.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # 70d2c2bdafc17581f6352efce88ef5b2b1447cfc

Date
May 26, 2020
Research Description
Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.13.36 WordPress Form Maker by 10Web plugin <= 1.13.35 - Authenticated SQL Injection (SQLi) vulnerability Authenticated SQL Injection (SQLi) vulnerability discovered by Vu Tien Hoa in WordPress Form Maker by 10Web plugin (versions <= 1.13.35).
Affected versions
max 1.13.36.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # 39f2b937cc8453e5b438df1d242bcfbebd61a1e9

Date
Apr 10, 2019
Research Description
Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.13.5 WordPress Form Maker by 10Web plugin <= 1.13.4 - Cross-Site Request Forgery (CSRF) vulnerability Cross-Site Request Forgery (CSRF) vulnerability found by Panagiotis Vagenas in WordPress Form Maker by 10Web plugin (versions <= 1.13.4).
Affected versions
max 1.13.5.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # 67be606edfc3db668d885122c871d5745831fa99

Date
Jul 12, 2020
Research Description
Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.13.40 WordPress Form Maker by 10Web plugin <= 1.13.39 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered by Andy Tyler in WordPress Form Maker by 10Web plugin (versions <= 1.13.39).
Affected versions
max 1.13.40.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # 77b9452b-41f3-4ba4-a84a-e49df0113f92

Date
-
Research Description
Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.13.40 Form Maker by 10Web &lt; 1.13.40 - Authenticated Reflected XSS The &#039;Form Maker by 10Web&#039; WordPress plugin is vulnerable to XSS in the &#039;blocked_ips_fm&#039; page. A logged-in site administrator who follows a crafted link will trigger arbitrary JavaScript code to be run in their browser in the context of their privileged account on the WordPress site.
Affected versions
max 1.13.40.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # 4e3c4624-7ae4-415c-8e54-a4b2049a4302

Date
-
Research Description
Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.13.36 Form Maker by 10Web &lt; 1.13.36 - Authenticated SQL Injection Authenticated (admin+) SQL injection in the Form Maker by 10Web WordPress Plugin 1.13.35 exists via the /wordpress/wp-admin/admin.php?page=blocked_ips_fm&amp;s=1&quot; s parameter. Edit (WPScanTeam): - Initial reported version (5.4.1) does not exist, confirmed to be 1.13.35 by researcher - May 25th, 2020 - details made public in other places - May 26th, 2020 - Escalated to WP Plugins Team
Affected versions
max 1.13.36.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # 81bb3d501efb863ea3fb621e320e351b2b1136bb

Date
Sep 07, 2023
Research Description
Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.15.20 WordPress Form Maker by 10Web Plugin < 1.15.20 is vulnerable to Arbitrary File Upload Update the WordPress Form Maker by 10Web plugin to the latest available version (at least 1.15.20). An unknown person discovered and reported this Arbitrary File Upload vulnerability in WordPress Form Maker by 10Web Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnerability has been fixed in version 1.15.20.
Affected versions
max 1.15.20.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # bc7ece1a-e917-48a3-9078-ee3d4a4e713c

Date
-
Research Description
Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.6.6 Form Maker 1.6.4 - front_end_form_maker.php Unspecified XSS The Form Maker by 10Web &ndash; Mobile-Friendly Drag &amp; Drop Contact Form Builder WordPress plugin was affected by a front_end_form_maker.php Unspecified XSS security vulnerability.
Affected versions
max 1.6.6.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # f45a20c2fbb3e6a529e1d5d9a7937aa8e1d93646

Date
Jun 14, 2023
Research Description
Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.15.17 Form Maker <= 1.15.16 - Missing Authorization in check_score The Form Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the check_score function in versions up to, and including, 1.15.16. This makes it possible for authenticated attackers, with subscriber-level privileges and above, to reveal the score of posts.
Affected versions
max 1.15.17.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # 8665ff6b0aa9dcafd405093d9ccfbd38e49025e7

Date
Sep 07, 2023
Research Description
Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.15.20 Form Maker by 10Web <= 1.15.19 - Unauthenticated Arbitrary File Upload The Form Maker by 10Web plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'type_signature' case of the save_db() function in versions up to, and including, 1.5.19. This makes it possible for unauthenticated attackers to upload arbitrary files, via the signature field, on the affected site's server which may make remote code execution possible.
Affected versions
max 1.15.20.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # 2ec8ebc9689dcd99b98b670a8d798b7e35ff31d5

Date
Oct 11, 2023
Research Description
Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder [form-maker] < 1.15.21 Form Maker <= 1.15.20 - Captcha Bypass The Form Maker plugin for WordPress is vulnerable to Captcha Bypass in versions up to, and including, 1.15.20 due to insufficient input verification. This makes it possible for unauthenticated attackers to automate form submissions.
Affected versions
max 1.15.21.
Status
vulnerable
Jun 19, 2026

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2026-11776

CVE, Research URL

CVE-2026-11776

Date
Jun 18, 2026
Research Description
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'groupids' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
max 1.15.44.
Status
vulnerable

Form Maker by 10Web &#8211; Mobile-Friendly Drag &amp; Drop Contact Form Builder # CVE-2026-11777

CVE, Research URL

CVE-2026-11777

Date
Jun 18, 2026
Research Description
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'name' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
max 1.15.44.
Status
vulnerable