Description
The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box input type) in form submissions in all versions up to, and including, 1.15.40. This is due to insufficient input sanitization (`sanitize_text_field` strips tags but not quotes) and missing output escaping when rendering submission data in the admin Submissions view. This makes it possible for unauthenticated attackers to inject arbitrary JavaScript through a form submission that executes in the browser of an administrator who views the submission details.
INFO
Published Date :
2026-04-14T02:25:48.339Z
Last Modified :
2026-04-14T14:04:52.784Z
Source :
Wordfence
AFFECTED PRODUCTS
The following products are affected by CVE-2026-4388 vulnerability.
| Vendors | Products |
|---|---|
| 10web |
|
| Wordpress |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-4388.