Ghostwire

CVE-2025-15441: The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping"...

UNKNOWN CVSS 0.0 EPSS 0.02%

Published: April 13, 2026 | Last Modified: April 13, 2026

Description

The Form Maker by 10Web WordPress plugin before 1.15.38 does not properly prepare SQL queries when the "MySQL Mapping" feature is in use, which could make SQL Injection attacks possible in certain contexts.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.02% (6th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References