CVE-2026-11776: Form Maker by 10Web <= 1.15.43 - Authenticated (Adminsitrator+) SQL Injection via 'groupids' Parameter
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic SQL Injection via the 'groupids' parameter in all versions up to, and including, 1.15.43 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
wordpress/form-maker-by-10webfrom your environment.If the plugin is not required, uninstall the Form Maker by 10Web plugin from the site to eliminate the vulnerable component.
- Configuration
Deactivate the Form Maker by 10Web plugin in the WordPress admin to prevent exploitation of the 'groupids' parameter until a safe update is available.
WordPress plugin: Form Maker by 10Web active = false - Compensating control
Restrict access to WordPress administrative interfaces (wp-admin) and administrative accounts to trusted IP addresses or networks, and reduce the number of administrator-level accounts to only those required.
- Operational
Audit database queries and access logs for signs of unauthorized queries or data exfiltration related to the plugin; rotate any credentials, API keys, or secrets that may have been stored in or exposed via the database.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11776?
The severity of CVE-2026-11776 is classified as medium with a score of 4.9.
How do I fix CVE-2026-11776?
To remediate CVE-2026-11776, update the Form Maker by 10Web plugin to the latest version beyond 1.15.43.
What type of vulnerability is CVE-2026-11776?
CVE-2026-11776 is an SQL Injection vulnerability.
What parameter is exploited in CVE-2026-11776?
The vulnerability in CVE-2026-11776 is exploited via the 'groupids' parameter.
Who is affected by CVE-2026-11776?
Authenticated users with Administrator privileges using Form Maker by 10Web versions up to 1.15.43 are affected by CVE-2026-11776.