Description
The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user-submitted values that are placed into notification email headers, allowing unauthenticated attackers to inject additional email headers, such as Bcc, into the emails the site sends when a submitted field value is configured to populate a header.
Published: 2026-09-11
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Email header injection
Action: Patch
AI Analysis

Impact

The MetForm WordPress plugin allows unauthenticated attackers to insert arbitrary email headers through poorly sanitized user input. This is a CWE-93 vulnerability involving improper neutralization of newline characters and other header elements. By placing newline characters in fields that populate notification headers, an attacker can add custom Bcc, Cc, or other header entries, potentially causing the for phishing or spam campaigns. The vulnerability does not provide remote code execution but can compromise email confidentiality and authenticity.

Affected Systems

All installations of the MetForm plugin with a version earlier than 4.1.9 are affected. The issue is specific to the Unauthenticated Email Header Injection via Notification Reply-To functionality within the plugin. Users running versions 4.1.8 and below are at risk, while versions 4.1.9 and later contain the fix.

Risk and Exploitability

The CVSS score for this flaw is 4.8, indicating a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be unauthenticated, as the flaw is triggered via publicly accessible form fields that populate email headers. While the exploitation requires no credentials and can be performed through normal form submission, the lack of a higher severity but still noteworthy risk of email abuse.

Generated by OpenCVE AI on September 11, 2026 at 16:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the MetForm plugin to version 4.1.9 or later, which neutralizes newline characters in fields used for email headers.
  • If an update is not immediately possible, disable or remove any form fields that populate notification email headers, thereby eliminating the attack surface.
  • Configure the email notification system to reject or strip any header values supplied by user input, ensuring that only trusted configuration values are used in email headers.

Generated by OpenCVE AI on September 11, 2026 at 16:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-543

Fri, 11 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-543

Fri, 11 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-93
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user-submitted values that are placed into notification email headers, allowing unauthenticated attackers to inject additional email headers, such as Bcc, into the emails the site sends when a submitted field value is configured to populate a header.
Title MetForm < 4.1.9 - Unauthenticated Email Header Injection via Notification Reply-To
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-11T12:06:35.387Z

Reserved: 2026-09-08T13:37:59.083Z

Link: CVE-2026-86813

cve-icon Vulnrichment

Updated: 2026-09-11T12:05:27.346Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T11:16:57.267

Modified: 2026-09-11T17:35:21.440

Link: CVE-2026-86813

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:15:05Z

Weaknesses
  • CWE-93

    Improper Neutralization of CRLF Sequences ('CRLF Injection')