CVE-2026-66616: WordPress Form Maker by 10Web plugin <= 1.15.46 - Cross Site Scripting (XSS) vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions.
Affected Software
1 affected component
10web WordPress Form Maker<=1.15.46
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is described as unauthenticated, so an attacker does not need a WordPress account or existing plugin privileges to attempt exploitation. Exploitation still requires user interaction, as indicated by the UI:R metric.
2
Which installations are affected?
WordPress sites using Form Maker by 10Web version 1.15.46 or earlier are affected according to the available information.
3
What impact could successful exploitation have?
The severity vector indicates low confidentiality, integrity, and availability impact, with scope changed. As an XSS issue, successful exploitation can execute attacker-controlled script in a victim's browser context.