CVE-2026-3330Disclosure

LOWCVSS 4.9 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate', 'username_search', and 'useremail_search' parameters in all versions up to, and including, 1.15.40. This is due to the `WDW_FM_Library::validate_data()` method calling `stripslashes()` on user input (removing WordPress's `wp_magic_quotes()` protection) and the `FMModelSubmissions_fm::get_labels_parameters()` function directly concatenating user-supplied values into SQL queries without using `$wpdb->prepare()`. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Additionally, the Submissions controller skips nonce verification for the `display` task, which means this vulnerability can be triggered via CSRF by tricking an administrator into clicking a crafted link.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-17: 2PoC Mentioned / Linked · 2026-04-17: 1Technical Details · 2026-04-17: 104-17
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-3330-form-maker-version-1-15-40-medium-vulnerability-proof-of-concept CVE-2026-3330 #WordPress plugin #vulnerability form-maker #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    An Atomicedge blog post announces a proof‑of‑concept attack for CVE‑2026‑3330 against the Form Maker WordPress plugin, but does not provide active exploitation evidence, patch info, or detailed technical data.

    0000039
    7 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3330 The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate', 'username_search', and 'useremail_search' param… https://www.cve.org/CVERecord?id=CVE-2026-3330

    Post summary

    The statement announces a SQL injection vulnerability (CVE‑2026‑3330) in the Form Maker plugin for WordPress, detailing the affected parameters.

    0000061
    57.2K followersView on X

Explore more