WordPress security by component
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
Plugin description
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor is a WordPress component with 22 published CVE records in this archive. The latest tracked vulnerability was published Jul 29, 2025; the highest CVE/CNA score is 8.3.
Plugin slug:
metformLatest vulnerability
CVE-2025-5684: MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor: Cross-site scripting
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
| Safe version |
|
||
|---|---|---|---|
| Jul 29, 2025 |
CVE-2025-5684
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor: Cross-site scripting
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Mar 27, 2025 |
CVE-2025-30914
Metform: Server-side request forgery
Metform is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE4.4
NVDPending
|
| Aug 17, 2024 |
CVE-2023-0714
Metform: Dangerous file upload
Metform is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE8.1
NVD9.8
|
| Jun 11, 2024 |
CVE-2024-4266
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor: Sensitive information exposure
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| May 06, 2024 |
CVE-2024-33570
Metform: A security weakness
Metform is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Mar 13, 2024 |
CVE-2024-1585
Metform Elementor Contact Form Builder: Cross-site scripting
Metform Elementor Contact Form Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jan 09, 2024 |
CVE-2023-6788
Metform Elementor Contact Form Builder: Cross-site request forgery
Metform Elementor Contact Form Builder is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Aug 31, 2023 |
CVE-2023-0689
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jul 12, 2023 |
CVE-2023-2517
Metform Elementor Contact Form Builder: Cross-site request forgery
Metform Elementor Contact Form Builder is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD4.3
|
| Jun 09, 2023 |
CVE-2023-1843
Metform Elementor Contact Form Builder: A security weakness
Metform Elementor Contact Form Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD5.3
|
| Jun 09, 2023 |
CVE-2023-0721
Metform Elementor Contact Form Builder: A security weakness
Metform Elementor Contact Form Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.3
NVD7.8
|
| Jun 09, 2023 |
CVE-2023-0710
Metform: Cross-site scripting
Metform is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.9
NVD5.4
|
| Jun 09, 2023 |
CVE-2023-0709
Metform: Cross-site scripting
Metform is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Jun 09, 2023 |
CVE-2023-0708
Metform: Cross-site scripting
Metform is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Jun 09, 2023 |
CVE-2023-0695
Metform: Cross-site scripting
Metform is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Jun 09, 2023 |
CVE-2023-0694
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE6.5
NVD4.3
|
| Jun 09, 2023 |
CVE-2023-0693
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE6.5
NVD4.3
|
| Jun 09, 2023 |
CVE-2023-0692
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Jun 09, 2023 |
CVE-2023-0691
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Jun 09, 2023 |
CVE-2023-0688
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Mar 02, 2023 |
CVE-2023-0084
Metform Elementor Contact Form Builder: Cross-site scripting
Metform Elementor Contact Form Builder is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Mar 02, 2023 |
CVE-2023-0085
Metform Elementor Contact Form Builder: A security weakness
Metform Elementor Contact Form Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|