Form Maker by 10Web <= 1.15.47 - Unauthenticated Reflected Cross-Site Scripting via 'inputs' Parameter Keys

Medium 6.1 CWE-79Fixed in 1.15.48
ID
WPSEC-2026-0479
Plugin
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder (form-maker)
Affected
from 1.13.3 before 1.15.48
Remediation
Update to 1.15.48 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
Attack surface
Form Maker by 10Web on WPSec AttackSurface
Fix released
Published

Description

The Form Maker by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the array keys of the 'inputs' parameter of the fm_reload_input AJAX action in versions 1.13.3 up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. Request values were sanitized but request array keys were not, and part of each key is reflected into the AJAX response, which is served as HTML, both as a response key and inside the generated field markup. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can trick a visitor into clicking a crafted link.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0