What is CVE-2026-15993?
The 'Form Maker by 10Web' plugin for WordPress (versions up to 1.15.44) contains a Blind SQL Injection vulnerability via the '{username}' placeholder in the Dynamic-Choice field's WHERE clause. This flaw arises from insufficient escaping of user-supplied parameters. Immediate update to the latest patched version is strongly recommended.
Azərbaycanca: WordPress üçün 'Form Maker by 10Web' plaginində (1.15.44 və aşağı versiyalar) 'Dynamic-Choice' sahəsindəki '{username}' placeholder-i vasitəsilə Blind SQL Injection zəifliyi aşkarlanıb. Bu, istifadəçi tərəfindən verilən parametrin kifayət qədər filtirlənməməsi səbəbindən baş verir. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: 10Web
FAQ2
Which versions of the 'Form Maker by 10Web' plugin are affected by CVE-2026-15993?
This vulnerability affects plugin versions up to and including 1.15.44.
Where does the Blind SQL Injection attack occur in CVE-2026-15993?
The attack occurs via the '{username}' placeholder located in the WHERE clause of the 'Dynamic-Choice' field.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.