PT-2026-33017 · Wpmet+1 · Metform Pro
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MetForm Pro versions prior to 3.9.8
Description
Improper Input Validation in payment integrations for Stripe and PayPal allows unauthenticated attackers to manipulate the payment amount. This occurs because the system trusts a user-submitted calculation field value without recomputing or validating it against the configured form price. The issue can be exploited via the
mf-calculation field in the form submission REST request when a form is configured with these specific settings.Recommendations
Update MetForm Pro to version 3.9.8 or later.
As a temporary mitigation, avoid using the
mf-calculation field in forms integrated with Stripe or PayPal until the update is applied.Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Metform Pro