WordPress security by component
Metform Elementor Contact Form Builder
Plugin description
Metform Elementor Contact Form Builder builds Elementor forms with a visual editor, customizable fields, submissions, and configurable form settings.
Metform Elementor Contact Form Builder (metform) is a WordPress plugin with 24 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 8.3.
Plugin slug:
metformLatest vulnerability
CVE-2026-86813: MetForm permits unauthenticated notification-header injection
MetForm before 4.1.9 does not neutralize newline characters in visitor-supplied values when a form field is configured to populate a notification email header. An unauthenticated attacker can inject additional headers such as Bcc into mail sent by the site.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-86813
MetForm permits unauthenticated notification-header injection
MetForm before 4.1.9 does not neutralize newline characters in visitor-supplied values when a form field is configured to populate a notification email header. An unauthenticated attacker can inject additional headers such as Bcc into mail sent by the site.
|
4.1.9 |
CVE4.8
NVDPending
|
| Aug 25, 2026 |
CVE-2026-18100
MetForm permits Contributor-level stored cross-site scripting
MetForm through 4.1.8 lets a Contributor or higher store script-capable input in the mf_form_id widget setting. A tag-free payload bypasses Elementor's save-time wp_kses_post filtering, and MetForm's script-tag str_replace transformation provides an additional render-time path for JavaScript execution.
|
4.2.0 |
CVE6.4
NVDPending
|
| Jul 29, 2025 |
CVE-2025-5684
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor: Cross-site scripting
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Mar 27, 2025 |
CVE-2025-30914
Metform: Server-side request forgery
Metform is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE4.4
NVDPending
|
| Aug 17, 2024 |
CVE-2023-0714
Metform: Dangerous file upload
Metform is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE8.1
NVD9.8
|
| Jun 11, 2024 |
CVE-2024-4266
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor: Sensitive information exposure
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| May 06, 2024 |
CVE-2024-33570
Metform: A security weakness
Metform is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Mar 13, 2024 |
CVE-2024-1585
Metform Elementor Contact Form Builder: Cross-site scripting
Metform Elementor Contact Form Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jan 09, 2024 |
CVE-2023-6788
Metform Elementor Contact Form Builder: Cross-site request forgery
Metform Elementor Contact Form Builder is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Aug 31, 2023 |
CVE-2023-0689
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jul 12, 2023 |
CVE-2023-2517
Metform Elementor Contact Form Builder: Cross-site request forgery
Metform Elementor Contact Form Builder is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD4.3
|
| Jun 09, 2023 |
CVE-2023-1843
Metform Elementor Contact Form Builder: A security weakness
Metform Elementor Contact Form Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD5.3
|
| Jun 09, 2023 |
CVE-2023-0721
Metform Elementor Contact Form Builder: A security weakness
Metform Elementor Contact Form Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.3
NVD7.8
|
| Jun 09, 2023 |
CVE-2023-0710
Metform: Cross-site scripting
Metform is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.9
NVD5.4
|
| Jun 09, 2023 |
CVE-2023-0709
Metform: Cross-site scripting
Metform is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Jun 09, 2023 |
CVE-2023-0708
Metform: Cross-site scripting
Metform is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Jun 09, 2023 |
CVE-2023-0695
Metform: Cross-site scripting
Metform is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Jun 09, 2023 |
CVE-2023-0694
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE6.5
NVD4.3
|
| Jun 09, 2023 |
CVE-2023-0693
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE6.5
NVD4.3
|
| Jun 09, 2023 |
CVE-2023-0692
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Jun 09, 2023 |
CVE-2023-0691
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Jun 09, 2023 |
CVE-2023-0688
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Mar 02, 2023 |
CVE-2023-0084
Metform Elementor Contact Form Builder: Cross-site scripting
Metform Elementor Contact Form Builder is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Mar 02, 2023 |
CVE-2023-0085
Metform Elementor Contact Form Builder: A security weakness
Metform Elementor Contact Form Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|