PT-2026-81188 · WordPress · Metform

·

CVE-2026-18100

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor versions prior to 4.1.9
Description Insufficient input sanitization and output escaping allow authenticated attackers with contributor-level access and above to perform Stored Cross-Site Scripting (XSS). This occurs via the mf form id Widget Setting, enabling the injection of arbitrary web scripts into pages that execute when accessed by users. The attack bypasses the wp kses post filter used by Elementor because the payload contains no HTML tags. Additionally, the use of the str replace() function to transform script tags into JavaScript template literal expressions creates an alternative delivery path for the scripts.
Recommendations Update MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor to version 4.1.9 or later. As a temporary mitigation, restrict access to the mf form id Widget Setting for users with contributor-level permissions.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18100

Affected Products

Metform