{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/form-maker--1.15.47/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:10web:form_maker:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-96813"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Form Maker (\u003c= 1.15.47)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress","cve-2026-96813"],"_cs_type":"advisory","_cs_vendors":["10Web"],"content_html":"\u003cp\u003eThe Form Maker by 10Web plugin for WordPress (versions 1.15.47 and below) is affected by a stored cross-site scripting (XSS) vulnerability, identified as CVE-2026-96813. The vulnerability exists within the Mark on Map feature, specifically due to insufficient input sanitization and output escaping on the longitude and latitude fields. An unauthenticated attacker can submit malicious payloads through these parameters, which are subsequently stored by the application. When a victim, such as an administrator or other user, views the page where this content is rendered, the script executes in their browser session. This can lead to session hijacking, unauthorized actions performed on behalf of the user, or redirection to malicious sites. Defenders should prioritize updating to a version beyond 1.15.47 once a patch is available and monitor web application logs for suspicious input containing script tags or event handlers.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a high risk to WordPress sites utilizing the Form Maker plugin. Successful exploitation allows unauthenticated attackers to execute malicious JavaScript, potentially compromising user accounts, bypassing security controls, or defacing site content. Since the vulnerability is stored, a single successful injection can impact every user who accesses the compromised page, creating a persistent threat until the malicious data is removed and the plugin is updated.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Form Maker by 10Web plugin to the latest version (above 1.15.47) immediately to resolve the lack of input sanitization.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to inspect input parameters related to the Mark on Map feature for suspicious script injection patterns (e.g., \u0026lt;script\u0026gt;, onerror, onload).\u003c/li\u003e\n\u003cli\u003eReview WordPress logs for unusual POST requests targeting form submission or map configuration endpoints that contain non-numeric characters in coordinates.\u003c/li\u003e\n\u003cli\u003eApply the principle of least privilege for WordPress administrative access to minimize the impact of potential session hijacking resulting from successful XSS exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T10:40:29Z","date_published":"2026-10-01T10:40:29Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96813/","summary":"The Form Maker by 10Web WordPress plugin contains a stored cross-site scripting vulnerability in longitude and latitude fields that allows unauthenticated attackers to execute arbitrary scripts in the context of other users.","title":"Stored XSS in Form Maker by 10Web WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-96813/"}],"language":"en","title":"CraftedSignal Threat Feed - Form Maker (\u003c= 1.15.47)","version":"https://jsonfeed.org/version/1.1"}