Skip to content
Threat Feed
high advisory

Stored XSS in Form Maker by 10Web WordPress Plugin

The Form Maker by 10Web WordPress plugin contains a stored cross-site scripting vulnerability in longitude and latitude fields that allows unauthenticated attackers to execute arbitrary scripts in the context of other users.

CVE search metadata

CVE search record: CVE-2026-96813. Severity: high. CVSS: 7.2. KEV: no. Product: Form Maker (<= 1.15.47). Brief: Stored XSS in Form Maker by 10Web WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96813/

The Form Maker by 10Web plugin for WordPress (versions 1.15.47 and below) is affected by a stored cross-site scripting (XSS) vulnerability, identified as CVE-2026-96813. The vulnerability exists within the Mark on Map feature, specifically due to insufficient input sanitization and output escaping on the longitude and latitude fields. An unauthenticated attacker can submit malicious payloads through these parameters, which are subsequently stored by the application. When a victim, such as an administrator or other user, views the page where this content is rendered, the script executes in their browser session. This can lead to session hijacking, unauthorized actions performed on behalf of the user, or redirection to malicious sites. Defenders should prioritize updating to a version beyond 1.15.47 once a patch is available and monitor web application logs for suspicious input containing script tags or event handlers.

Impact

The vulnerability poses a high risk to WordPress sites utilizing the Form Maker plugin. Successful exploitation allows unauthenticated attackers to execute malicious JavaScript, potentially compromising user accounts, bypassing security controls, or defacing site content. Since the vulnerability is stored, a single successful injection can impact every user who accesses the compromised page, creating a persistent threat until the malicious data is removed and the plugin is updated.

Recommendation

  • Update the Form Maker by 10Web plugin to the latest version (above 1.15.47) immediately to resolve the lack of input sanitization.
  • Implement a Web Application Firewall (WAF) rule to inspect input parameters related to the Mark on Map feature for suspicious script injection patterns (e.g., <script>, onerror, onload).
  • Review WordPress logs for unusual POST requests targeting form submission or map configuration endpoints that contain non-numeric characters in coordinates.
  • Apply the principle of least privilege for WordPress administrative access to minimize the impact of potential session hijacking resulting from successful XSS exploitation.

Immediate actions

Upgrade Form Maker by 10Web plugin to version 1.15.48 or later

IT Operations 24h

Mitigations

Patch WordPress plugin vulnerability CVE-2026-96813

immediate IT Operations

CVE-2026-96813