CVE-2018-25346: 10web Form Maker
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through the FormMakerSQLMapping and generete_csv actions. Attackers can submit POST requests with malicious SQL payloads in the name and search_labels parameters to extract, modify, or escalate privileges within the WordPress database.
Affected products
- 10web Form Maker: up to and including 1.12.24
Published 2026-05-23. Last modified 2026-07-23.