CVE 9.3 CRITICAL

WordPress Form Maker by 10Web plugin <= 1.15.38 - SQL Injection vulnerability_CVE-2026-39502

9.3 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

Description

Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.

AI Analysis

Unauthenticated SQL Injection vulnerability in Form Maker by 10Web plugin

Basic Information

ID CVE-2026-39502
Source Patchstack
Published Jun 15, 2026 at 20:17

Affected Product

Vendor 10Web
Product Form Maker by 10Web
Version 1.15.38
Affected Versions 10Web Form Maker by 10Web n/a

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor 10Web
Product Form Maker by 10Web
Version 1.15.38

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.