CVE-2026-16977: Form Maker by 10Web < 1.15.45 - Subscriber+ SQL Injection via display_name
Published Aug 12, 2026
·Updated
The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection.
Affected Software
1 affected component
10web Form Maker by 10Web<1.15.45
Event History
Aug 12, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:19 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-16977?
CVE-2026-16977 has a risk score of 55, indicating a moderate severity of the vulnerability.
2
How do I fix CVE-2026-16977?
To mitigate CVE-2026-16977, update the Form Maker by 10Web plugin to version 1.15.45 or later.
3
What type of vulnerability is CVE-2026-16977?
CVE-2026-16977 is classified as a SQL Injection vulnerability.
4
Who is affected by CVE-2026-16977?
Subscribers using the Form Maker by 10Web plugin versions prior to 1.15.45 are affected by CVE-2026-16977.
5
What can an attacker do with CVE-2026-16977?
An attacker can exploit CVE-2026-16977 to perform second-order SQL injection attacks via user-controlled input.