CVE-2026-16977
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
12/08/2026
Last modified:
12/08/2026
Description
The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH



