CVE-2025-48341: WordPress Form Maker by 10Web plugin <= 1.15.33 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Maker by 10Web allows Stored XSS. This issue affects Form Maker by 10Web: from n/a through 1.15.33.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Maker by 10Web form-maker allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through <= 1.15.33.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48341?
CVE-2025-48341 is classified as a Stored XSS vulnerability with a medium severity level.
How do I fix CVE-2025-48341?
To fix CVE-2025-48341, update 10Web Form Maker to version 1.15.34 or later.
What are the potential consequences of CVE-2025-48341?
Exploitation of CVE-2025-48341 can lead to unauthorized script execution in the context of an authenticated user's session.
Which versions of 10Web Form Maker are affected by CVE-2025-48341?
CVE-2025-48341 affects all versions of 10Web Form Maker up to and including 1.15.33.
Is CVE-2025-48341 prevalent in WordPress environments?
Yes, CVE-2025-48341 is particularly concerning in WordPress environments using 10Web Form Maker, as it can lead to serious security risks.