PT-2026-32277 · 10Web · Form Maker

Hiariz

·

Published

2026-04-13

·

Updated

2026-04-27

·

CVE-2025-15441

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Form Maker by 10Web WordPress plugin versions prior to 1.15.38
Description Improper preparation of SQL queries occurs when the "MySQL Mapping" feature is active, which may enable SQL Injection attacks in certain contexts.
Recommendations Update the plugin to version 1.15.38 or later. As a temporary workaround, consider disabling the "MySQL Mapping" feature to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-15441

Affected Products

Form Maker