← back to popular plugins
wordfence / plugin · metform

MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor

metform
total installs
600,000
total vulns
3
critical
0
high
0
medium
2
low
1
latest vuln
patched
3
unpatched
0
avg time to patch
vulnerabilities (3)
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 4.1.0 - Unauthenticated Form Submission Exposure via Forgeable Cookie Value
low ✓ patched
cvss score 3.7
cwe CWE-287: Improper Authentication
published Jan 23, 2026
The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.1.0. This is due to the use of a forgeable cookie value derived only from the entry ID and current user ID without a server-side secret. This makes it possible for unauthenticated attackers to access form submission entry data via MetForm shortcodes for entries created within the transient TTL (default is 15 minutes).
MetForm <= 4.0.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via `mf-template` DOM Element
medium ✓ patched
cvss score 6.4
cwe CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
published Jul 29, 2025
The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `mf-template` DOM Element in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Metform <= 3.9.2 - Authenticated (Admin+) Server-Side Request Forgery
medium ✓ patched
cvss score 5.5
cwe CWE-918: Server-Side Request Forgery (SSRF)
published Mar 27, 2025
The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.9.2. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.