CVE-2026-15993

Form Maker by 10Web <= 1.15.44 - Authenticated (Subscriber+) SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause in all versions up to, and including, 1.15.44 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This requires that a form is configured with a DB-backed dynamic choice field whose WHERE template references the {username} placeholder, and the attacker must first set their own display_name to a SQL payload via the standard WordPress profile edit screen before triggering the fm_reload_input AJAX endpoint.


We have discovered 4,941 live websites that are affected by CVE-2026-15993.

Run a Free Instant Scan




Affected Software

Product  Form Maker
Category Form Builders
Vulnerable Domains4,941 live websites (74% of Form Maker install base)
Vulnerable Versions
  • from 0 through 1.15.44
Vulnerable Versions Count150 versions ( 52% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Aug 15, 2026
  • Updated - Aug 17, 2026

Credits

  • R4mbb (finder)

Website Distribution by Country

Number of websites using CVE-2026-15993
United States1,555 websites



Germany492 websites
Italy338 websites
GB274 websites
Netherlands258 websites
France247 websites
India134 websites
Russia131 websites
Canada113 websites
Spain110 websites

Website Distribution by TLD

Number of websites using CVE-2026-15993
.com2,036 websites
.org277 websites
.de262 websites
.nl234 websites
.it211 websites
.co.uk172 websites
.net125 websites
.ru110 websites
.fr102 websites
.ca78 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-15993

Top websites that are affected by CVE-2026-15993. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.org United States***,***
*******.com Spain***,***
***.tw Taiwan***,***
*********************.org South Africa***,***
****************.org United States***,***
***********.org United States***,***
***********.eu Germany***,***
****************.ca United States***,***
*******.org United States***,***
************.com United States***,***
See full domain list

FAQ

CVE-2026-15993 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Form Maker
A total of 4,941 websites have been identified as vulnerable to CVE-2026-15993, based on global website indexing conducted by WebTechSurvey.
The Form Maker is affected by the CVE-2026-15993 vulnerability.
Form Maker versions up to and including 1.15.44 are vulnerable to CVE-2026-15993.

References