Junglewise Threat Intelligence

CVE-2026-85645: 10Web Form Maker reflected XSS in bulk_action parameter

CVE-2026-85645 · Severity: medium · CVSS 6.1 · Published 2026-09-10

Technologies: 10Web Form Maker. Vendors: 10Web.

Executive brief

The Form Maker plugin for WordPress, used to create contact forms and manage form submissions, contains a reflected cross-site scripting vulnerability in its admin submissions page. An attacker can craft a malicious link and trick an administrator into clicking it, allowing arbitrary JavaScript to execute in their browser session with full admin privileges, potentially leading to account compromise or malware installation.

Technical details

The vulnerability is a reflected XSS in the bulk_action parameter of the Submissions_fm.php controller. The parameter is sanitized via sanitize_key() in the execute() method but is later used unsafely in the bulk_action() method without proper output escaping. The code constructs a redirect URL using add_query_arg() and passes unsanitized user input from $_GET that was not included in the delete_keys array. An unauthenticated attacker can send a specially crafted URL to a logged-in admin that reflects malicious JavaScript. The vulnerability affects all versions up to and including 1.15.46. No authentication is required for the initial delivery, but successful exploitation requires social engineering to trick an admin into clicking the malicious link.

Affected products

  • 10Web Form Maker up to and including 1.15.46

Timeline

  • 2026-09-10: disclosed

References

Related threats