Junglewise Threat Intelligence

CVE-2026-39502: 10Web Form Maker SQL injection

CVE-2026-39502 · Severity: critical · CVSS 9.3 · Published 2026-06-15

Technologies: 10Web Form Maker. Vendors: 10Web.

Executive brief

Form Maker by 10Web is a popular WordPress plugin used to create and manage complex forms on websites. A critical security flaw allows unauthorized individuals to interact directly with the website's database without needing a password. This could lead to the theft of sensitive customer data, exposure of administrative credentials, or disruption of the website's operations.

Technical details

A SQL injection vulnerability exists in the Form Maker by 10Web plugin for WordPress due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is accessible to unauthenticated remote attackers, meaning no login credentials or specific user roles are required to exploit it. By sending specially crafted web requests, an attacker can bypass security filters to query, modify, or delete data within the underlying database. This vulnerability has been assigned a CVSS score of 9.3, reflecting its high impact on data confidentiality and potential for automated mass exploitation. Users are advised to update to version 1.15.39 or later to remediate the issue.

Affected products

  • 10Web Form Maker by 10Web <= 1.15.38

Timeline

  • 2026-01-16: other: Vulnerability reported by Nguyen Ba Khanh
  • 2026-04-08: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: patched: Patch released in version 1.15.39
  • 2026-06-15: advisory: NVD publication date

References

Related threats