CVE-2025-15441

The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which could make SQL Injection attacks possible in certain contexts.
Configurations

No configuration.

History

13 Apr 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8
CWE CWE-89

13 Apr 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-13 07:16

Updated : 2026-06-17 08:37


NVD link : CVE-2025-15441

Mitre link : CVE-2025-15441

CVE.ORG link : CVE-2025-15441


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')