high · CVSS v3 7.2
CVE-2026-96813
The Form Maker plugin for WordPress is vulnerable to stored XSS via map longitude/latitude fields. Unauthenticated attackers can inject scri
Overview
The Form Maker plugin for WordPress is vulnerable to stored XSS via map longitude/latitude fields. Unauthenticated attackers can inject scripts that run when users view affected pages. This can lead to defacement, cookie theft, or malicious redirects.
Description
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Impact
Stored XSS can compromise confidentiality by stealing session cookies, integrity by allowing content tampering, and availability if malicious scripts disrupt page functionality. Site visitors and administrators are the primary impacted parties.
Remediation
Update the plugin to version 1.15.48 or later. If update is not possible, disable or remove the map fields, or apply input sanitization and output escaping. Implement a Content Security Policy to block inline scripts and use a web application firewall to filter XSS payloads.
Risk context
High severity (CVSS 7.2) with no EPSS data. The vulnerability is exploitable by unauthenticated users, making it a priority for immediate patching.
Affected products
- 10Web Form Maker
- WordPress Form Maker plugin
Scores
- Severity
- high
- CVSS v2
- 6.4
- CVSS v3
- 7.2
- CVSS v4
- —
- EPSS
- —