WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through the FormMakerSQLMapping and generete_csv actions. Attackers can submit POST requests with malicious SQL payloads in the name and search_labels parameters to extract, modify, or escalate privileges within the WordPress database.
History

Tue, 26 May 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 23 May 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Sat, 23 May 2026 18:45:00 +0000

Type Values Removed Values Added
Description WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through the FormMakerSQLMapping and generete_csv actions. Attackers can submit POST requests with malicious SQL payloads in the name and search_labels parameters to extract, modify, or escalate privileges within the WordPress database.
Title WordPress Form Maker Plugin 1.12.24 SQL Injection via admin-ajax.php
First Time appeared 10web
10web form Maker
Weaknesses CWE-89
CPEs cpe:2.3:a:10web:form_maker:*:*:*:*:*:wordpress:*:*
Vendors & Products 10web
10web form Maker
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-05-23T18:30:48.238Z

Updated: 2026-05-26T14:11:11.123Z

Reserved: 2026-05-23T14:49:40.257Z

Link: CVE-2018-25346

cve-icon Vulnrichment

Updated: 2026-05-26T14:10:55.462Z

cve-icon NVD

Status : Deferred

Published: 2026-05-23T19:16:54.593

Modified: 2026-05-26T19:37:32.587

Link: CVE-2018-25346

cve-icon Redhat

No data.