CVE-2025-15441: Form Maker < 1.15.38 - SQL Injection
Published Apr 13, 2026
·Updated
The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which could make SQL Injection attacks possible in certain contexts.
Affected Software
1 affected component
10web Form Maker<1.15.38
Event History
Apr 13, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-15441?
CVE-2025-15441 is considered a high severity vulnerability due to the potential for SQL Injection attacks.
2
How do I fix CVE-2025-15441?
To fix CVE-2025-15441, update the Form Maker plugin to version 1.15.38 or later.
3
Which versions of Form Maker are affected by CVE-2025-15441?
Form Maker versions prior to 1.15.38 are affected by CVE-2025-15441.
4
What type of attack does CVE-2025-15441 enable?
CVE-2025-15441 enables SQL Injection attacks due to improper SQL query preparation.
5
Is CVE-2025-15441 specific to certain environments?
CVE-2025-15441 can be exploited in contexts where the 'MySQL Mapping' feature is used.