# Form Maker by 10Web <= 1.15.47 - Unauthenticated Reflected Cross-Site Scripting via 'inputs' Parameter Keys

- **ID:** WPSEC-2026-0479
- **Plugin:** Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder (`form-maker`), https://wordpress.org/plugins/form-maker/
- **Affected versions:** from 1.13.3 before 1.15.48
- **Fixed in:** 1.15.48 (Update to 1.15.48 or later.)
- **Severity:** Medium 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/form-maker
- **Fix released:** 2026-09-28
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0479/

## Description

The Form Maker by 10Web plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the array keys of the 'inputs' parameter of the fm_reload_input AJAX action in versions 1.13.3 up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. Request values were sanitized but request array keys were not, and part of each key is reflected into the AJAX response, which is served as HTML, both as a response key and inside the generated field markup. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can trick a visitor into clicking a crafted link.

## References

- https://wpsec.com/vuln/WPSEC-2026-0479/
- https://plugins.svn.wordpress.org/form-maker/tags/1.15.48/
- https://wordpress.org/plugins/form-maker/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0479/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
