← WordPress Vulnerabilities
WordPress security by component

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published May 05, 2026; the highest CVE/CNA score is 7.5.

Plugin slug: form-maker-by-10web-mobile-friendly-drag-drop-contact-form-builder

CVE-2026-3359: Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: SQL injection

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.15.42.

PublishedMay 05, 2026
Known safe version> 1.15.42
Safe version
May 05, 2026 CVE-2026-3359
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: SQL injection
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.15.42.
> 1.15.42
CVE7.5
NVDPending