Description
The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the -MySQL Mapping- feature is in use, which could make SQL Injection attacks possible in certain contexts.
CVSS 6.8EPSS 0.272%Risque 0.7
Voir la source- Publication
- 2026-04-13 07:16:07
- Versions concernées
- < 1.15.38
- Type
- Package
- Vecteur
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N