The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its email notifications, allowing unauthenticated attackers to inject arbitrary markup into the administrator and submitter notification emails the site sends.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Oct 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1070 CWE-20 |
Wed, 07 Oct 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its email notifications, allowing unauthenticated attackers to inject arbitrary markup into the administrator and submitter notification emails the site sends. | |
| Title | MetForm < 4.3.1 - Unauthenticated HTML Injection in Notification Emails via Field Shortcodes | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-07T06:47:51.929Z
Reserved: 2026-09-08T14:32:26.457Z
Link: CVE-2026-86833
No data.
Status : Received
Published: 2026-10-07T07:17:01.730
Modified: 2026-10-07T07:17:01.730
Link: CVE-2026-86833
No data.
OpenCVE Enrichment
Updated: 2026-10-07T08:30:15Z