Impact
The MetForm plugin is affected by a stored cross‑site scripting flaw that allows a contributor‑level user or higher to embed arbitrary JavaScript within the mf‑template element. When a target user views the compromised page, the malicious script runs in the victim’s browser. Attackers could steal session cookies, perform actions under the victim’s identity, or load external malicious content. The weakness is a classic input validation and output escaping failure classified as CWE‑79.
Affected Systems
This issue affects the MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin distributed by roxnor. All released versions up to and including 4.0.1 are vulnerable. Customers using earlier versions should verify their installation and consider upgrading.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score is less than 1%, implying low exploitation probability in the current period. The vulnerability is not yet in the CISA KEV catalog. Exploitation requires authenticated Contributor-level access, meaning the attacker must already have moderate privileges within the WordPress site. Attackers can inject malicious code through the admin interface by editing an existing form or creating a new one. Because the payload is stored, every user who opens the affected page will execute the script until the infection is removed.
OpenCVE Enrichment
EUVD