CVE-2026-93773: WordPress Mollie Forms plugin <= 2.11.0 - SQL Injection vulnerability
Published Sep 23, 2026
·Updated
Contributor SQL Injection in Mollie Forms <= 2.11.0 versions.
Affected Software
1 affected component
Mollie Mollie Forms<=2.11.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Mollie Forms Pluginto a version that resolves this vulnerability.Fixed in 2.11.1
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs Contributor-level access to a WordPress site using an affected Mollie Forms version. The vulnerability is remotely reachable and does not require user interaction once that access is available.
2
What is the likely impact of successful exploitation?
The CVSS vector indicates high confidentiality impact and a low availability impact. It also indicates that the vulnerability can affect resources beyond the vulnerable security authority, while integrity impact is rated none.
3
Which plugin versions are affected?
Mollie Forms versions up to and including 2.11.0 are identified as affected.