PT-2026-81188 · WordPress · Metform
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor versions prior to 4.1.9
Description
Insufficient input sanitization and output escaping allow authenticated attackers with contributor-level access and above to perform Stored Cross-Site Scripting (XSS). This occurs via the
mf form id Widget Setting, enabling the injection of arbitrary web scripts into pages that execute when accessed by users. The attack bypasses the wp kses post filter used by Elementor because the payload contains no HTML tags. Additionally, the use of the str replace() function to transform script tags into JavaScript template literal expressions creates an alternative delivery path for the scripts.Recommendations
Update MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor to version 4.1.9 or later.
As a temporary mitigation, restrict access to the
mf form id Widget Setting for users with contributor-level permissions.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Metform