Impact
The MetForm WordPress plugin prior to version 4.3.1 fails to sanitize form-field values before inserting them into the HTML body of notification emails. This allows an unauthenticated attacker who can submit a form to inject arbitrary markup into emails sent to administrators and form submitters, potentially leading to phishing, UI manipulation or execution of malicious scripts within the email client.
Affected Systems
WordPress sites running the MetForm plugin version 4.3.1 or earlier are affected. The vulnerability applies to all installations of the plugin regardless of the site’s domain or user level, as the flaw arises from the plugin’s lack of sanitization when handling form submissions.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is not available, but because the flaw can be triggered by any unauthenticated form submission, the potential for exploitation is high in environments where the plugin is publicly exposed. The vulnerability is not listed in the CISA KEV catalog. An attacker can leverage the flaw by crafting a form submission that contains malicious HTML or JavaScript, which will then be sent in notification emails to administrators and potentially other recipients.
OpenCVE Enrichment