EIP-2026-113763

PRE-CVE

WordPress Plugin Form Maker 5.4.1 - 's' SQL Injection (Authenticated)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-113763. PoCs published by SunCSR.

AI-analyzed exploit summary This exploit demonstrates an authenticated SQL injection vulnerability in the WordPress Form Maker plugin (version <= 5.4.1) via the 's' parameter in the blocked_ips_fm page. It includes a proof-of-concept HTTP request and SQLMap commands to exploit the vulnerability.

Description

WordPress Plugin Form Maker 5.4.1 - 's' SQL Injection (Authenticated)

Exploits (1)

exploitdb WORKING POC
by SunCSR · textwebappsphp
https://www.exploit-db.com/exploits/48509

This exploit demonstrates an authenticated SQL injection vulnerability in the WordPress Form Maker plugin (version <= 5.4.1) via the 's' parameter in the blocked_ips_fm page. It includes a proof-of-concept HTTP request and SQLMap commands to exploit the vulnerability.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin Form Maker <= 5.4.1
Auth required
Prerequisites: Authenticated access to WordPress admin panel · Form Maker plugin version <= 5.4.1
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026