10Web 的 Form Maker 是一款适用于 WordPress 的、支持移动设备的拖放式联系表单构建器插件。该插件在 1.15.48 及更早版本中存在反射型跨站脚本(Reflected Cross-Site Scripting, XSS)漏洞,原因是未对 “inputs(数组键)” 参数进行充分的输入清理和输出转义。这使得未认证的攻击者能够在网页中注入任意 Web 脚本,如果攻击者能成功诱使受害者执行某些操作(例如点击恶意链接),则注入的脚本将在用户浏览器中执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| 10web | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | ≤ 1.15.48 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 10web | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | 0 ~ 1.15.48 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105885 | 8.8 HIGH | WordPress Slider by 10Web plugin <= 1.2.62 - PHP Object Injection vulnerability |
| CVE-2026-107742 | 7.2 HIGH | 10Web Booster <= 2.34.8 - Unauthenticated Stored Cross-Site Scripting via Comment Author N |
| CVE-2026-42711 | 7.1 HIGH | WordPress Slider by 10Web plugin <= 1.2.63 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-42715 | 7.1 HIGH | WordPress Photo Gallery by 10Web plugin <= 1.8.47 - Cross Site Scripting (XSS) vulnerabili |
No comments yet