Executive brief
Form Maker is a WordPress plugin used to create and manage web forms on WordPress websites. An unauthenticated attacker can inject malicious scripts into forms, allowing them to steal visitor data, hijack user accounts, or redirect users to malicious sites. The vulnerability can be exploited without requiring legitimate access to the website.
Technical details
The vulnerability is an unauthenticated cross-site scripting (XSS) flaw in Form Maker by 10Web plugin versions up to 1.15.47. The root cause involves improper input validation or output encoding in form processing, allowing attackers to inject arbitrary JavaScript into form fields. Exploitation requires user interaction (e.g., clicking a malicious link or visiting a crafted page containing the payload). The attack is network-reachable and does not require authentication. An attacker can steal session cookies, capture form submissions, redirect users, or perform actions on behalf of visitors. No official patch has been released as of the advisory publication date; Patchstack has issued a temporary mitigation rule.
Affected products
- 10Web Form Maker <=1.15.47
Timeline
- 2026-08-20: disclosed
- 2026-08-19: advisory: Patchstack advisory published