CVE-2025-15441

The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which could make SQL Injection attacks possible in certain contexts.
Configurations

No configuration.

History

No history.

Information

Published : 2026-04-13 07:16

Updated : 2026-06-17 08:37


NVD link : CVE-2025-15441

Mitre link : CVE-2025-15441

CVE.ORG link : CVE-2025-15441


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')