Impact
The MetForm WordPress plugin allows unauthenticated attackers to insert arbitrary email headers through poorly sanitized user input. This is a CWE-93 vulnerability involving improper neutralization of newline characters and other header elements. By placing newline characters in fields that populate notification headers, an attacker can add custom Bcc, Cc, or other header entries, potentially causing the for phishing or spam campaigns. The vulnerability does not provide remote code execution but can compromise email confidentiality and authenticity.
Affected Systems
All installations of the MetForm plugin with a version earlier than 4.1.9 are affected. The issue is specific to the Unauthenticated Email Header Injection via Notification Reply-To functionality within the plugin. Users running versions 4.1.8 and below are at risk, while versions 4.1.9 and later contain the fix.
Risk and Exploitability
The CVSS score for this flaw is 4.8, indicating a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be unauthenticated, as the flaw is triggered via publicly accessible form fields that populate email headers. While the exploitation requires no credentials and can be performed through normal form submission, the lack of a higher severity but still noteworthy risk of email abuse.
OpenCVE Enrichment