Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Information

Software Type Plugin
Software Slug form-maker (view on wordpress.org)
Software Status Active
Software Author 10web
Software Website 10web.io
Software Downloads 5,107,040
Software Active Installs 30,000
Software Record Last Updated July 21, 2026

Showing 1-20 of 39 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
Form Maker by 10Web <= 1.15.43 - Authenticated (Adminsitrator+) SQL Injection via 'groupids' Parameter Patched CVE-2026-11776 4.9 Muhammad Arsalan Diponegoro (tripoloski) June 17, 2026
Form Maker by 10Web <= 1.15.43 - Authenticated (Administrator+) SQL Injection via 'name' Parameter Patched CVE-2026-11777 4.9 Muhammad Arsalan Diponegoro (tripoloski) June 17, 2026
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.42 - Unauthenticated SQL Injection via 'inputs' Patched CVE-2026-3359 7.5 type5afe May 4, 2026
Form Maker by 10Web <= 1.15.40 - Authenticated (Administrator+) SQL Injection via 'ip_search' Parameter Patched CVE-2026-3330 4.9 Sein Linn April 16, 2026
Form Maker by 10Web <= 1.15.40 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Text Box Patched CVE-2026-4388 7.2 Naoya Takahashi (nakko) April 13, 2026
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.38 - Unauthenticated SQL Injection Patched CVE-2026-39502 7.5 Nguyen Ba Khanh April 8, 2026
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder < 1.15.38 - Unauthenticated SQL Injection Patched CVE-2025-15441 7.5 hiariz March 23, 2026
Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via Hidden Field Patched CVE-2026-1058 7.1 Supakiad S. (m3ez) February 2, 2026
Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via SVG file Patched CVE-2026-1065 7.2 Supakiad S. (m3ez) February 2, 2026
Form Maker by 10Web <= 1.15.33 - Authenticated (Administrator+) Stored Cross-Site Scripting Patched CVE-2025-48341 4.4 Nabil Irawan May 19, 2025
Form Maker by 10Web <= 1.15.31 - Authenticated (Administrator+) Stored Cross-Site Scripting Patched CVE-2024-10680 5.5 Dmitrii Ignatyev March 26, 2025
Form Maker by 10Web <= 1.15.29 - Authenticated (Admin+) Stored Cross-Site Scripting Patched CVE-2024-10560 4.4 Dmitrii Ignatyev March 3, 2025
Form Maker by 10Web <= 1.15.29 - Authenticated (Admin+) Stored Cross-Site Scripting Patched CVE-2024-10558 4.4 Dmitrii Ignatyev March 2, 2025
Form Maker by 10Web <= 1.15.32 - Authenticated (Admin+) Stored Cross-Site Scripting Patched CVE-2024-13053 4.4 Dmitrii Ignatyev February 7, 2025
Form Maker by 10Web <= 1.15.32 - Authenticated (Admin+) Stored Cross-Site Scripting Patched CVE-2024-13605 4.4 Dmitrii Ignatyev February 3, 2025
Form Maker by 10Web <= 1.15.30 - Authenticated (Admin+) Stored Cross-Site Scripting Patched CVE-2024-10562 4.4 Dmitrii Ignatyev December 17, 2024
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library Patched CVE-2024-5020 6.4 Webbernaut December 3, 2024
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.30 - Reflected Cross-Site Scripting via add_query_arg Parameter Patched CVE-2024-10265 6.1 vgo0 November 10, 2024
Form Maker <= 1.15.27 - Authenticated (Administrator+) Stored Cross-Site Scripting Patched CVE-2024-8633 5.5 Joel Indra September 25, 2024
Form Maker by 10Web <= 1.15.26 - Reflected Cross-Site Scripting Patched CVE-2024-43220 6.1 Le Ngoc Anh August 9, 2024

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation