Sceawere

Vulnerability Detail

CVE-2026-103998UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Reflected XSS in Form Maker

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
3h ago
Vendor
10web
Product
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'inputs (array key)' parameter in all versions up to, and including, 1.15.48 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-10-10T05:16:39.380Z",
  "pubdate": "2026-10-10T05:16:39.380Z",
  "executiveSummary": "The Form Maker by 10Web plugin for WordPress, in versions up to and including 1.15.48, contains a Reflected Cross-Site Scripting (XSS) vulnerability.\nThis flaw exists due to insufficient sanitization and output escaping of the 'inputs' array key parameter within the plugin's code.\nThe vulnerability allows unauthenticated attackers to inject and execute arbitrary JavaScript code within the context of a victim's browser session.\nSuccessful exploitation requires an attacker to convince a target user to interact with a crafted URL, typically via social engineering.\nThe impact includes the potential for session hijacking, unauthorized actions performed on behalf of the user, and the exfiltration of sensitive information.\nGiven that the attack does not require authentication, the risk is significant for sites utilizing this plugin, as it provides a vector for cross-origin attacks and site-wide user compromise.",
  "technicalDetails": "The vulnerability is classified as Reflected Cross-Site Scripting, stemming from improper handling of user-supplied data in the 'inputs' parameter.\nThe root cause is identified as the application's failure to perform adequate input validation or contextual output encoding before rendering the parameter's value back to the browser.\nWhen a user navigates to a crafted URL, the server processes the malicious payload contained within the 'inputs' parameter. Since the application fails to neutralize HTML special characters, the payload is interpreted by the browser as executable script.\nThe execution flow involves the attacker crafting a malicious link containing a JavaScript payload. When an authenticated administrator or user clicks this link, the reflected script executes within the security context of the affected WordPress site.\nBecause the payload resides in the client's browser, it can access the DOM, perform unauthorized requests using the victim's session cookies, or redirect the user to a malicious site.\nThe vulnerability is present in versions up to 1.15.48. It is accessible over the network without requiring any prior authentication, making it a highly accessible vector for remote attackers.\nOnce triggered, the malicious script operates with the victim's permissions. If an administrator is targeted, the attacker could potentially create new administrative accounts, modify plugin settings, or inject persistent backdoors into the site's theme or configuration files.\nThis XSS variant is particularly dangerous because the malicious content is delivered directly to the user from the legitimate site's domain, often bypassing basic security filters that rely on external blocklists.\nThe lack of strict input sanitization on the 'inputs' array key indicates a breakdown in secure coding practices within the affected component, specifically regarding the handling of HTTP GET or POST parameters that are reflected in the HTML response."
}
CVE-2026-103998: Reflected XSS in Form Maker (MEDIUM Severity, CVSS: 6.1) | Sceawere