10Web · Form Maker · CVE-2026-11776
**Name of the Vulnerable Software and Affected Versions**
Form Maker by 10Web versions prior to 1.15.44
**Description**
The Form Maker by 10Web plugin for WordPress contains a generic SQL Injection issue. This occurs because the user-supplied `groupids` parameter is not properly escaped and the SQL query is not sufficiently prepared. Authenticated attackers with administrator-level access or higher can append additional SQL queries to existing ones to extract sensitive information from the database.
**Recommendations**
Update to a version newer than 1.15.43.
As a temporary workaround, restrict access to the `groupids` parameter until the update is applied.