CVE-2026-16977: Unknown Form Maker By 10web
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection.
Affected products
- Unknown Form Maker By 10web: before 1.15.45 (fixed in 1.15.45)
Published 2026-08-12. Last modified 2026-08-26.