CVE-2026-86832
Received Received - Intake

Unauthenticated Information Exposure in MetForm WordPress Plugin

Vulnerability report for CVE-2026-86832, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: WPScan

Description

The MetForm WordPress plugin before 4.3.1 does not properly restrict access to form submission data, allowing unauthenticated attackers to view submitter information through the REST API.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
metform metform to 4.3.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The MetForm WordPress plugin before version 4.3.1 has a vulnerability where it does not properly restrict access to form submission data. This allows unauthenticated attackers to view submitter information through the REST API.

Detection Guidance

To detect this vulnerability, check if your MetForm plugin version is below 4.3.1. You can verify the installed version via WordPress admin panel under Plugins or by inspecting the plugin files. Additionally, monitor REST API requests to the /wp-json/metform/v1/entries endpoint for unauthorized access attempts.

Impact Analysis

Attackers can access sensitive submitter information without authentication. This includes data from contact forms, surveys, and quizzes, potentially exposing personal details of users who submitted forms.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized access to personal data. Organizations may face legal penalties, fines, and reputational damage for failing to protect sensitive user information.

Mitigation Strategies

Immediately update the MetForm plugin to version 4.3.1 or later through the WordPress admin panel. If updating is not possible, consider temporarily disabling the plugin until an update is applied. Review server logs for suspicious API access to the affected endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86832. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart