Description

The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which could make SQL Injection attacks possible in certain contexts.

INFO

Published Date :

2026-04-13T06:00:11.088Z

Last Modified :

2026-04-13T06:00:11.088Z

Source :

WPScan
AFFECTED PRODUCTS

The following products are affected by CVE-2025-15441 vulnerability.

Vendors Products
10web
  • Form Maker
Wordpress
  • Wordpress
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-15441.

CVSS Vulnerability Scoring System