← WordPress Vulnerabilities
WordPress security by component

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder is a WordPress component with 34 published CVE records in this archive. The latest tracked vulnerability was published Jun 18, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: form-maker

CVE-2026-11777: Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: SQL injection

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.15.43.

PublishedJun 18, 2026
Known safe version> 1.15.43
Safe version
Jun 18, 2026 CVE-2026-11777
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: SQL injection
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.15.43.
> 1.15.43
CVE4.9
NVDPending
Jun 18, 2026 CVE-2026-11776
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: SQL injection
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.15.43.
> 1.15.43
CVE4.9
NVDPending
Jun 15, 2026 CVE-2026-39502
Form Maker by 10Web: SQL injection
Form Maker by 10Web is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 1.15.38.
1.15.39
CVE9.3
NVDPending
May 23, 2026 CVE-2018-25346
Form Maker: SQL injection
Form Maker is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.12.24.
> 1.12.24
CVE7.1
NVDPending
Apr 17, 2026 CVE-2026-3330
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: SQL injection
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.15.40.
> 1.15.40
CVE4.9
NVDPending
Apr 14, 2026 CVE-2026-4388
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: Cross-site scripting
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.15.40.
> 1.15.40
CVE7.2
NVDPending
Feb 03, 2026 CVE-2026-1065
Form Maker by 10Web: Cross-site scripting
Form Maker by 10Web is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVDPending
Feb 03, 2026 CVE-2026-1058
Form Maker: Cross-site scripting
Form Maker is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
May 19, 2025 CVE-2025-48341
Form Maker by 10Web: Cross-site scripting
Form Maker by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
May 15, 2025 CVE-2024-13053
Form Maker by 10Web: Cross-site scripting
Form Maker by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Apr 16, 2025 CVE-2024-10680
Form Maker by 10Web: Cross-site scripting
Form Maker by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Mar 25, 2025 CVE-2024-10560
Form Maker by 10Web: Cross-site scripting
Form Maker by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE3.5
NVDPending
Mar 24, 2025 CVE-2024-10558
Form Maker by 10Web: Cross-site scripting
Form Maker by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE3.5
NVDPending
Feb 24, 2025 CVE-2024-13605
Form Maker by 10Web: Cross-site scripting
Form Maker by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Jan 07, 2025 CVE-2024-10562
Form Maker by 10Web: Cross-site scripting
Form Maker by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE2.7
NVDPending
Nov 10, 2024 CVE-2024-10265
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: Cross-site scripting
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Sep 26, 2024 CVE-2024-8633
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: Cross-site scripting
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder is affected by cross-site scripting. Exploitation requires at least administrator-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.5
NVD4.8
Aug 12, 2024 CVE-2024-43220
Form Maker by 10Web: Cross-site scripting
Form Maker by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Jul 01, 2024 CVE-2024-6130
Form Maker by 10Web: Cross-site scripting
Form Maker by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Jun 04, 2024 CVE-2023-48290
Form Maker by 10Web: A security weakness
Form Maker by 10Web is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
May 14, 2024 CVE-2024-34437
Form Maker by 10Web: Cross-site scripting
Form Maker by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Apr 27, 2024 CVE-2024-2258
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: Cross-site scripting
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD5.4
Apr 17, 2024 CVE-2024-32534
Form Maker by 10Web: Cross-site scripting
Form Maker by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
Apr 09, 2024 CVE-2024-2112
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: Sensitive information exposure
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.9
NVD7.5
Jan 27, 2024 CVE-2024-0667
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: Cross-site request forgery
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD6.3
Oct 18, 2023 CVE-2023-45071
Form Maker: Cross-site scripting
Form Maker is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Oct 18, 2023 CVE-2023-45070
Form Maker: Cross-site scripting
Form Maker is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Oct 16, 2023 CVE-2023-4666
Form Maker by 10Web: A security weakness
Form Maker by 10Web is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8
Oct 25, 2022 CVE-2022-3300
Form Maker by 10Web: SQL injection
Form Maker by 10Web is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD7.2
May 30, 2022 CVE-2022-1564
Form Maker by 10Web: Cross-site scripting
Form Maker by 10Web is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Aug 16, 2021 CVE-2021-24526
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: Cross-site scripting
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
May 23, 2019 CVE-2019-10866
Form Maker: SQL injection
Form Maker is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Apr 29, 2019 CVE-2019-11590
Form Maker: Filesystem traversal
Form Maker is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.8
NVD8.8
Apr 27, 2018 CVE-2018-10504
Form Maker: A security weakness
Form Maker is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.8
NVD7.8