← WordPress Vulnerabilities
WordPress security by component

MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor

MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor is a WordPress component with 22 published CVE records in this archive. The latest tracked vulnerability was published Jul 29, 2025; the highest CVE/CNA score is 8.3.

Plugin slug: metform

CVE-2025-5684: MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor: Cross-site scripting

MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedJul 29, 2025
Safe version guidanceSee mitigation notes
Safe version
Jul 29, 2025 CVE-2025-5684
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor: Cross-site scripting
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Mar 27, 2025 CVE-2025-30914
Metform: Server-side request forgery
Metform is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE4.4
NVDPending
Aug 17, 2024 CVE-2023-0714
Metform: Dangerous file upload
Metform is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE8.1
NVD9.8
Jun 11, 2024 CVE-2024-4266
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor: Sensitive information exposure
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVD7.5
May 06, 2024 CVE-2024-33570
Metform: A security weakness
Metform is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD8.8
Mar 13, 2024 CVE-2024-1585
Metform Elementor Contact Form Builder: Cross-site scripting
Metform Elementor Contact Form Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jan 09, 2024 CVE-2023-6788
Metform Elementor Contact Form Builder: Cross-site request forgery
Metform Elementor Contact Form Builder is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD5.4
Aug 31, 2023 CVE-2023-0689
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVDPending
Jul 12, 2023 CVE-2023-2517
Metform Elementor Contact Form Builder: Cross-site request forgery
Metform Elementor Contact Form Builder is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Jun 09, 2023 CVE-2023-1843
Metform Elementor Contact Form Builder: A security weakness
Metform Elementor Contact Form Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD5.3
Jun 09, 2023 CVE-2023-0721
Metform Elementor Contact Form Builder: A security weakness
Metform Elementor Contact Form Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.3
NVD7.8
Jun 09, 2023 CVE-2023-0710
Metform: Cross-site scripting
Metform is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.9
NVD5.4
Jun 09, 2023 CVE-2023-0709
Metform: Cross-site scripting
Metform is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Jun 09, 2023 CVE-2023-0708
Metform: Cross-site scripting
Metform is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Jun 09, 2023 CVE-2023-0695
Metform: Cross-site scripting
Metform is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Jun 09, 2023 CVE-2023-0694
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE6.5
NVD4.3
Jun 09, 2023 CVE-2023-0693
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE6.5
NVD4.3
Jun 09, 2023 CVE-2023-0692
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVD4.3
Jun 09, 2023 CVE-2023-0691
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVD4.3
Jun 09, 2023 CVE-2023-0688
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE6.5
NVD6.5
Mar 02, 2023 CVE-2023-0084
Metform Elementor Contact Form Builder: Cross-site scripting
Metform Elementor Contact Form Builder is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Mar 02, 2023 CVE-2023-0085
Metform Elementor Contact Form Builder: A security weakness
Metform Elementor Contact Form Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3