← back to popular plugins
wordfence / plugin · metform
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
metform
total installs
600,000
total vulns
3
critical
0
high
0
medium
2
low
1
latest vuln
—
patched
3
unpatched
0
avg time to patch
—
vulnerabilities
(3)
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 4.1.0 - Unauthenticated Form Submission Exposure via Forgeable Cookie Value
low
✓ patched
The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.1.0. This is due to the use of a forgeable cookie value derived only from the entry ID and current user ID without a server-side secret. This makes it possible for unauthenticated attackers to access form submission entry data via MetForm shortcodes for entries created within the transient TTL (default is 15 minutes).
MetForm <= 4.0.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via `mf-template` DOM Element
medium
✓ patched
cve id
CVE-2025-5684 ↗
cvss score
6.4
cwe
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
published
Jul 29, 2025
The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `mf-template` DOM Element in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Metform <= 3.9.2 - Authenticated (Admin+) Server-Side Request Forgery
medium
✓ patched
cve id
CVE-2025-30914 ↗
cvss score
5.5
cwe
CWE-918: Server-Side Request Forgery (SSRF)
published
Mar 27, 2025
The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.9.2. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.