Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-86832 1 Wordpress-extensions 1 Metform 2026-10-04 5.3 Medium
The MetForm WordPress plugin before 4.3.1 does not properly restrict access to form submission data, allowing unauthenticated attackers to view submitter information through the REST API.
CVE-2026-86834 1 Wordpress-extensions 1 Metform 2026-10-04 3.7 Low
The MetForm WordPress plugin before 4.3.1 does not properly restrict access to a debug file it writes to the web root on every form submission when its HubSpot Forms integration is enabled, allowing unauthenticated attackers to read upstream API response data, including correlation identifiers and cookies.
CVE-2026-103339 2 Wordpress-extensions, Wpmet 2 Metform, Metform 2026-10-01 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet Metform metform allows Stored XSS.This issue affects Metform: from n/a through 4.3.0.