CVE-2026-86833 PUBLISHED

MetForm < 4.3.1 - Unauthenticated HTML Injection in Notification Emails via Field Shortcodes

Assigner: WPScan
Reserved: 08.09.2026 Published: 07.10.2026 Updated: 07.10.2026

The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its email notifications, allowing unauthenticated attackers to inject arbitrary markup into the administrator and submitter notification emails the site sends.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS Score: 5.4

Product Status

Vendor Unknown
Product MetForm
Versions Default: unaffected
  • affected from 0 to 4.3.1 (excl.)

Credits

  • vuxvinh finder
  • WPScan coordinator

References

Problem Types

  • CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE