Description
The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its email notifications, allowing unauthenticated attackers to inject arbitrary markup into the administrator and submitter notification emails the site sends.
Published: 2026-10-07
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized HTML injection into notification emails
Action: Apply Patch
AI Analysis

Impact

The MetForm WordPress plugin prior to version 4.3.1 fails to sanitize form-field values before inserting them into the HTML body of notification emails. This allows an unauthenticated attacker who can submit a form to inject arbitrary markup into emails sent to administrators and form submitters, potentially leading to phishing, UI manipulation or execution of malicious scripts within the email client.

Affected Systems

WordPress sites running the MetForm plugin version 4.3.1 or earlier are affected. The vulnerability applies to all installations of the plugin regardless of the site’s domain or user level, as the flaw arises from the plugin’s lack of sanitization when handling form submissions.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. The EPSS score is not available, but because the flaw can be triggered by any unauthenticated form submission, the potential for exploitation is high in environments where the plugin is publicly exposed. The vulnerability is not listed in the CISA KEV catalog. An attacker can leverage the flaw by crafting a form submission that contains malicious HTML or JavaScript, which will then be sent in notification emails to administrators and potentially other recipients.

Generated by OpenCVE AI on October 7, 2026 at 08:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade MetForm to version 4.3.1 or later.
  • If immediate upgrade is not feasible, disable or remove email notifications that include user-provided content until a patch is available.
  • Review and sanitize any custom email templates within MetForm to remove or escape user input before sending.
  • Patch the plugin’s code to properly escape or filter form inputs before they are inserted into emails if you have development access.

Generated by OpenCVE AI on October 7, 2026 at 08:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1070
CWE-20

Wed, 07 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its email notifications, allowing unauthenticated attackers to inject arbitrary markup into the administrator and submitter notification emails the site sends.
Title MetForm < 4.3.1 - Unauthenticated HTML Injection in Notification Emails via Field Shortcodes
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T06:47:51.929Z

Reserved: 2026-09-08T14:32:26.457Z

Link: CVE-2026-86833

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T07:17:01.730

Modified: 2026-10-07T07:17:01.730

Link: CVE-2026-86833

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T08:30:15Z

Weaknesses
  • CWE-1070

    Serializable Data Element Containing non-Serializable Item Elements

  • CWE-20

    Improper Input Validation