---
id: CVE-2025-15441
title: >-
  The Form Maker by 10Web  WordPress plugin before 1.15.38 does not properly
  prepare SQL queries when the "MySQL Mapping" feature is in use, which could
  make SQL Injection attacks possible in certain contexts.
summary: >-
  The Form Maker by 10Web  WordPress plugin before 1.15.38 does not properly
  prepare SQL queries when the "MySQL Mapping" feature is in use, which could
  make SQL Injection attacks possible in certain contexts.
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-89
published: '2026-04-13'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15441'
references:
  - url: 'https://wpscan.com/vulnerability/41f69b0a-4d17-4a6b-b803-ea1c370e3cc0/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00272
epssPercentile: 0.17643
ingestedAt: '2026-09-30T22:27:27.753Z'
---

## Overview

The Form Maker by 10Web  WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which could make SQL Injection attacks possible in certain contexts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
