What is CVE-2026-16977?
CVE-2026-16977 is a critical SQL injection vulnerability in the Form Maker by 10Web WordPress plugin before version 1.15.45. Due to improper parameterization of a user-controlled value in a dynamic SQL query for a database-backed choice field, subscriber-level users can perform second-order SQL injection. Immediate plugin update is strongly recommended.
Azərbaycanca: CVE-2026-16977, Form Maker by 10Web WordPress plaginində 1.15.45 versiyasından əvvəl kritik SQL injection zəifliyidir. Dinamik SQL sorğusunda istifadəçi tərəfindən idarə olunan dəyərin düzgün parametrləşdirilməməsi səbəbindən abunəçi səviyyəli istifadəçilər ikinci dərəcəli SQL injection həyata keçirə bilər. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: 10Web
FAQ2
Which WordPress plugin is affected by CVE-2026-16977?
CVE-2026-16977 affects the Form Maker by 10Web WordPress plugin before version 1.15.45.
What level of user privilege is required to exploit this vulnerability?
Exploiting this vulnerability requires subscriber-level user privileges.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.