CVE-2026-16977

Form Maker by 10Web < 1.15.45 - Subscriber+ SQL Injection via display_name

The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection.


We have discovered 4,941 live websites that are affected by CVE-2026-16977.

Run a Free Instant Scan




Affected Software

Product  Form Maker
Category Form Builders
Vulnerable Domains4,941 live websites (74% of Form Maker install base)
Vulnerable Versions
  • from 0 through 1.15.45
Vulnerable Versions Count150 versions ( 52% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Aug 12, 2026
  • Updated - Aug 12, 2026

Credits

  • Revanth Meesala (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-16977
United States1,555 websites



Germany492 websites
Italy338 websites
GB274 websites
Netherlands258 websites
France247 websites
India134 websites
Russia131 websites
Canada113 websites
Spain110 websites

Website Distribution by TLD

Number of websites using CVE-2026-16977
.com2,036 websites
.org277 websites
.de262 websites
.nl234 websites
.it211 websites
.co.uk172 websites
.net125 websites
.ru110 websites
.fr102 websites
.ca78 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-16977

Top websites that are affected by CVE-2026-16977. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.org United States***,***
*******.com Spain***,***
***.tw Taiwan***,***
*********************.org South Africa***,***
****************.org United States***,***
***********.org United States***,***
***********.eu Germany***,***
****************.ca United States***,***
*******.org United States***,***
************.com United States***,***
See full domain list

FAQ

CVE-2026-16977 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Form Maker
A total of 4,941 websites have been identified as vulnerable to CVE-2026-16977, based on global website indexing conducted by WebTechSurvey.
The Form Maker is affected by the CVE-2026-16977 vulnerability.
Form Maker versions up to 1.15.45 are vulnerable to CVE-2026-16977.
CVE-2026-16977 is resolved in version 1.15.45 of Form Maker.