Showing 1 vulnerability on this page for Form Maker

Signals CISA KEV Ransomware Nuclei
10web vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WordPress Form Maker Plugin 1.12.24 SQL Injection via admin-ajax.php

WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through the FormMakerSQLMapping and generete_csv actions. Attackers can submit POST requests with malicious SQL payloads in the name and search_labels parameters to extract, modify, or escalate privileges within the WordPress database.

CWE-89May 23, 2026
CVSS7.1v4.0EPSS0.197%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX