AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-16977

HIGH · CVSS 8.1 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Form Maker by 10Web plugin for WordPress versions prior to 1.15.45 is vulnerable to second-order SQL injection due to improper parameterization of user-controlled input in dynamic SQL queries. This flaw allows subscriber-level users to manipulate database queries, potentially leading to unauthorized data access or modification. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-16977
Severity
HIGH
CVSS
8.1
EPSS
0.22%
WordPress

Original NVD Description

The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection.