Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet Metform metform allows Stored XSS.This issue affects Metform: from n/a through 4.3.0.
Published: 2026-10-01
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Stored XSS that can execute arbitrary scripts in users’ browsers
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a stored Cross‑Site Scripting flaw where the Metform plugin does not properly neutralize user input before rendering it on a page. An attacker can inject malicious JavaScript that will run whenever any user visits the affected page, potentially hijacking sessions, defacing content, or stealing credentials. The weakness corresponds to CWE‑79 and the CVSS score of 6.5 indicates a medium severity impact.

Affected Systems

The affected asset is the WordPress Metform plugin (Wpmet:Metform). All releases from the earliest known version through 4.3.0 are vulnerable. The published fix applies to version 4.3.1 and later, which removes the stored XSS code path.

Risk and Exploitability

Because this is a stored XSS, exploitation requires an attacker to supply input that is saved and later displayed to users. An attacker could submit data through any form or administrative interface that the plugin processes. The EPSS score is not available and the issue is not listed in CISA KEV, but the CVSS score of 6.5 suggests realistic risk if the plugin is exposed to the public. An attacker with no special privileges can exploit the flaw by creating or modifying content that the plugin subsequently renders.

Generated by OpenCVE AI on October 1, 2026 at 14:58 UTC.

Remediation

Vendor Solution

Update the WordPress Metform plugin to the latest available version (at least 4.3.1).


OpenCVE Recommended Actions

  • Update the Metform plugin to version 4.3.1 or newer to remove the stored XSS vulnerability.
  • Configure the WordPress instance to enforce content‑security‑policy headers that restrict script execution from untrusted sources until the plugin is fully patched.
  • If an update cannot be performed immediately, restrict the use of the Metform plugin or disable all form‑creation features that allow user input, and/or apply manual input sanitization to the fields used by the plugin until the official patch is applied.

Generated by OpenCVE AI on October 1, 2026 at 14:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet Metform metform allows Stored XSS.This issue affects Metform: from n/a through 4.3.0.
Title WordPress Metform plugin <= 4.3.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-01T13:12:11.502Z

Reserved: 2026-09-30T12:43:33.093Z

Link: CVE-2026-103339

cve-icon Vulnrichment

Updated: 2026-10-01T13:12:04.707Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T13:17:08.477

Modified: 2026-10-01T14:34:35.357

Link: CVE-2026-103339

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')