← WordPress Vulnerabilities
WordPress security by component

Metform Elementor Contact Form Builder

Metform Elementor Contact Form Builder builds Elementor forms with a visual editor, customizable fields, submissions, and configurable form settings.

Metform Elementor Contact Form Builder (metform) is a WordPress plugin with 24 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 8.3.

Plugin slug: metform

CVE-2026-86813: MetForm permits unauthenticated notification-header injection

MetForm before 4.1.9 does not neutralize newline characters in visitor-supplied values when a form field is configured to populate a notification email header. An unauthenticated attacker can inject additional headers such as Bcc into mail sent by the site.

PublishedSep 11, 2026
Known safe version4.1.9
Published vulnerabilities for metform
Safe version
Sep 11, 2026 CVE-2026-86813
MetForm permits unauthenticated notification-header injection
MetForm before 4.1.9 does not neutralize newline characters in visitor-supplied values when a form field is configured to populate a notification email header. An unauthenticated attacker can inject additional headers such as Bcc into mail sent by the site.
4.1.9
CVE4.8
NVDPending
Aug 25, 2026 CVE-2026-18100
MetForm permits Contributor-level stored cross-site scripting
MetForm through 4.1.8 lets a Contributor or higher store script-capable input in the mf_form_id widget setting. A tag-free payload bypasses Elementor's save-time wp_kses_post filtering, and MetForm's script-tag str_replace transformation provides an additional render-time path for JavaScript execution.
4.2.0
CVE6.4
NVDPending
Jul 29, 2025 CVE-2025-5684
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor: Cross-site scripting
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Mar 27, 2025 CVE-2025-30914
Metform: Server-side request forgery
Metform is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE4.4
NVDPending
Aug 17, 2024 CVE-2023-0714
Metform: Dangerous file upload
Metform is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE8.1
NVD9.8
Jun 11, 2024 CVE-2024-4266
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor: Sensitive information exposure
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVD7.5
May 06, 2024 CVE-2024-33570
Metform: A security weakness
Metform is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD8.8
Mar 13, 2024 CVE-2024-1585
Metform Elementor Contact Form Builder: Cross-site scripting
Metform Elementor Contact Form Builder is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Jan 09, 2024 CVE-2023-6788
Metform Elementor Contact Form Builder: Cross-site request forgery
Metform Elementor Contact Form Builder is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD5.4
Aug 31, 2023 CVE-2023-0689
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVDPending
Jul 12, 2023 CVE-2023-2517
Metform Elementor Contact Form Builder: Cross-site request forgery
Metform Elementor Contact Form Builder is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Jun 09, 2023 CVE-2023-1843
Metform Elementor Contact Form Builder: A security weakness
Metform Elementor Contact Form Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD5.3
Jun 09, 2023 CVE-2023-0721
Metform Elementor Contact Form Builder: A security weakness
Metform Elementor Contact Form Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.3
NVD7.8
Jun 09, 2023 CVE-2023-0710
Metform: Cross-site scripting
Metform is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.9
NVD5.4
Jun 09, 2023 CVE-2023-0709
Metform: Cross-site scripting
Metform is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Jun 09, 2023 CVE-2023-0708
Metform: Cross-site scripting
Metform is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Jun 09, 2023 CVE-2023-0695
Metform: Cross-site scripting
Metform is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Jun 09, 2023 CVE-2023-0694
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE6.5
NVD4.3
Jun 09, 2023 CVE-2023-0693
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE6.5
NVD4.3
Jun 09, 2023 CVE-2023-0692
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVD4.3
Jun 09, 2023 CVE-2023-0691
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVD4.3
Jun 09, 2023 CVE-2023-0688
Metform: Sensitive information exposure
Metform is affected by sensitive information exposure. Exploitation requires an authenticated subscriber account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE6.5
NVD6.5
Mar 02, 2023 CVE-2023-0084
Metform Elementor Contact Form Builder: Cross-site scripting
Metform Elementor Contact Form Builder is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Mar 02, 2023 CVE-2023-0085
Metform Elementor Contact Form Builder: A security weakness
Metform Elementor Contact Form Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3