MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 4.1.0 - Unauthenticated Form Submission Exposure via Forgeable Cookie Value
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
Minimum safe version
4.1.1
Update to 4.1.1 or later to address 26 fixable vulnerabilities
MetForm <= 4.0.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via `mf-template` DOM Element
CVE-2025-30914
WordPress Metform Elementor Contact Form Builder Plugin <= 3.2.4 is vulnerable to Arbitrary File Upload
CVE-2024-4266
CVE-2024-33570
CVE-2024-2791
CVE-2024-1585
CVE-2023-6788
WordPress Metform Elementor Contact Form Builder Plugin <= 3.4.0 is vulnerable to Broken Access Control
CVE-2023-0689
CVE-2023-2517
WordPress Metform Elementor Contact Form Builder Plugin <= 3.3.0 is vulnerable to Cross Site Scripting (XSS)
WordPress Metform Elementor Contact Form Builder Plugin <= 3.3.0 is vulnerable to Cross Site Scripting (XSS)
WordPress Metform Elementor Contact Form Builder Plugin <= 3.3.0 is vulnerable to CSV Injection
WordPress Metform Elementor Contact Form Builder Plugin <= 3.3.1 is vulnerable to Sensitive Data Exposure
WordPress Metform Elementor Contact Form Builder Plugin <= 3.3.0 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-0710
WordPress Metform Elementor Contact Form Builder Plugin <= 3.3.1 is vulnerable to Sensitive Data Exposure
WordPress Metform Elementor Contact Form Builder Plugin <= 3.3.1 is vulnerable to Sensitive Data Exposure
WordPress Metform Elementor Contact Form Builder Plugin <= 3.3.1 is vulnerable to Sensitive Data Exposure
WordPress Metform Elementor Contact Form Builder Plugin <= 3.3.1 is vulnerable to Sensitive Data Exposure
CVE-2023-1843
WordPress Metform Elementor Contact Form Builder Plugin <= 3.2.1 is vulnerable to Bypass Vulnerability
CVE-2023-0084
CVE-2022-1442