The Form Maker plugin for WordPress, developed by 10Web, has a security vulnerability that allows attackers with administrator-level permissions to inject harmful web scripts into pages. This can happen when the admin settings are not properly sanitized and escaped. This issue only affects multi-site installations and sites where unfiltered_html is disabled.