Impact
The vulnerability is a stored Cross‑Site Scripting flaw where the Metform plugin does not properly neutralize user input before rendering it on a page. An attacker can inject malicious JavaScript that will run whenever any user visits the affected page, potentially hijacking sessions, defacing content, or stealing credentials. The weakness corresponds to CWE‑79 and the CVSS score of 6.5 indicates a medium severity impact.
Affected Systems
The affected asset is the WordPress Metform plugin (Wpmet:Metform). All releases from the earliest known version through 4.3.0 are vulnerable. The published fix applies to version 4.3.1 and later, which removes the stored XSS code path.
Risk and Exploitability
Because this is a stored XSS, exploitation requires an attacker to supply input that is saved and later displayed to users. An attacker could submit data through any form or administrative interface that the plugin processes. The EPSS score is not available and the issue is not listed in CISA KEV, but the CVSS score of 6.5 suggests realistic risk if the plugin is exposed to the public. An attacker with no special privileges can exploit the flaw by creating or modifying content that the plugin subsequently renders.
OpenCVE Enrichment