10Web · Form Maker · CVE-2025-15441
**Name of the Vulnerable Software and Affected Versions**
The Form Maker by 10Web WordPress plugin versions prior to 1.15.38
**Description**
Improper preparation of SQL queries occurs when the "MySQL Mapping" feature is active, which may enable SQL Injection attacks in certain contexts.
**Recommendations**
Update the plugin to version 1.15.38 or later.
As a temporary workaround, consider disabling the "MySQL Mapping" feature to minimize the risk of exploitation.