CVE-2026-16977 - Form Maker by 10Web < 1.15.45 - Subscriber+ SQL Injection via display_name
CVE ID :CVE-2026-16977
Published : Aug. 12, 2026, 6:19 a.m. | 1 hour, 9 minutes ago
Description :The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 12, 2026, 6:19 a.m. | 1 hour, 9 minutes ago
Description :The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...