Impact
The MetForm WordPress plugin, versions 2.2.1 through 4.3.0, can be configured to enable a HubSpot Forms integration. When this integration is active, the plugin writes a debug file to the web‑root on every form submission. The file contains upstream API response data, including correlation identifiers and cookies, and is accessible without authentication. An attacker can read this file, potentially revealing sensitive request details, session tokens, or other data that could facilitate further compromise.
Affected Systems
WordPress sites that have the MetForm plugin installed in versions before 4.3.1 and have the HubSpot Forms integration enabled are affected. Site administrators should be aware that any user able to access the site root can read this debug file.
Risk and Exploitability
The vulnerability is exploitable from any public internet‑reachable server that hosts the affected WordPress installation, as it requires no authentication. While EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, the risk of sensitive information leakage remains significant. An attacker can simply request the debug file directly via HTTP GET, making the attack straightforward and likely to succeed if the file is reachable. The potential confidentiality impact is high because the file exposes session cookie data and correlation identifiers.
OpenCVE Enrichment