rootpwn

high · CVSS v3 7.2

CVE-2026-96813

The Form Maker plugin for WordPress is vulnerable to stored XSS via map longitude/latitude fields. Unauthenticated attackers can inject scri

Overview

The Form Maker plugin for WordPress is vulnerable to stored XSS via map longitude/latitude fields. Unauthenticated attackers can inject scripts that run when users view affected pages. This can lead to defacement, cookie theft, or malicious redirects.

Description

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Impact

Stored XSS can compromise confidentiality by stealing session cookies, integrity by allowing content tampering, and availability if malicious scripts disrupt page functionality. Site visitors and administrators are the primary impacted parties.

Remediation

Update the plugin to version 1.15.48 or later. If update is not possible, disable or remove the map fields, or apply input sanitization and output escaping. Implement a Content Security Policy to block inline scripts and use a web application firewall to filter XSS payloads.

Risk context

High severity (CVSS 7.2) with no EPSS data. The vulnerability is exploitable by unauthenticated users, making it a priority for immediate patching.

Affected products

  • 10Web Form Maker
  • WordPress Form Maker plugin

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.2
CVSS v4
—
EPSS
—

XSS WordPress FormMaker StoredXSS InputSanitization WebSecurity HighSeverity

← All CVEs