CVE-2023-45071 HIGH

CVE-2023-45071: WordPress Form Maker by 10Web Plugin <= 1.15.18 is vulnerable to Cross Site Scripting (XSS)

Vendor 10Web Form Builder Team
Product Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
Weakness CWE-79 · XSS
Published October 18, 2023
Last update April 28, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin <= 1.15.18 versions.

Explanation of Vulnerability in Simple Terms

02Summary

Form Maker by 10Web contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages viewed by site visitors. An attacker can craft a malicious link or form submission that executes JavaScript in the browser of anyone who interacts with the affected form. The vulnerability affects versions up to 1.15.18 and requires user interaction to exploit.

What an attacker can do

03Attacker Capabilities

Inject and execute malicious JavaScript in the browsers of site visitors who interact with affected forms.

Potential impact on your site

04Site Impact

Attackers can steal visitor data, redirect users, or deface forms; your site's reputation and visitor trust are at risk.

Conditions required to exploit

05Prerequisites

Site visitor must click a malicious link or interact with a crafted form submission; no authentication required.

Key dates

06Disclosure timeline

October 18, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE