CVE-2026-4388Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box input type) in form submissions in all versions up to, and including, 1.15.40. This is due to insufficient input sanitization (`sanitize_text_field` strips tags but not quotes) and missing output escaping when rendering submission data in the admin Submissions view. This makes it possible for unauthenticated attackers to inject arbitrary JavaScript through a form submission that executes in the browser of an administrator who views the submission details.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-14); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-14: 3Mentions · 2026-04-15: 1Technical Details · 2026-04-14: 304-1404-15
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-143
Disclosure3
2026-04-151
Disclosure1
Full discourse4 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4388 📊 Severity: 7.2 🚨 Risk Level: High 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4388 #CVE-2026-4388 #CVE #High #Wordpress #CyberSecurity #InfoSec https://t.co/DYr0cv7pLA

    Post summary

    The tweet announces a newly identified CVE-2026-4388 affecting WordPress with a severity of 7.2, providing a link to the NVD entry but no further technical or exploit details.

    0000034
    137 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4388 The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box input type) in form submissions in all versions… https://www.cve.org/CVERecord?id=CVE-2026-4388

    Post summary

    A stored XSS vulnerability (CVE‑2026‑4388) has been disclosed in the Form Maker plugin for WordPress, affecting all versions via the Matrix field, with no PoC, exploit code, active exploitation, or patch mentioned.

    0000051
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4388 Stored Cross-Site Scripting in Form Maker by 10Web Plugin for WordPress 1.15.40 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4388

    Post summary

    The entry announces CVE-2026-4388 as a stored XSS flaw in the Form Maker plugin for WordPress version 1.15.40, with no evidence of exploitation or mitigation details.

    0000023
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-4388 The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Bo… CVSS 7.2 Full analysis → https://sec.kaitan.id/cves/CVE-2026-4388 #WordPress #CyberSecurity #InfoSec

    Post summary

    The post announces CVE-2026‑4388 as a stored XSS flaw in the 10Web Form Maker plugin, noting a CVSS score of 7.2 and linking to a full analysis, but it does not mention PoC, exploitation, or fixes.

    000000
    144 followersView on X

Explore more