Sceawere
Vulnerability Detail
CVE-2026-86833UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MetForm Stored Email XSS Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 3h ago
- Vendor
- Unknown
- Product
- MetForm
- Attack Type
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its email notifications, allowing unauthenticated attackers to inject arbitrary markup into the administrator and submitter notification emails the site sends.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-07T07:17:01.730Z",
"pubdate": "2026-10-07T07:17:01.730Z",
"executiveSummary": "The MetForm WordPress plugin, in versions prior to 4.3.1, contains a critical vulnerability related to improper input validation and output encoding within its email notification system.\nThis vulnerability is classified as an Injection vulnerability, specifically Stored Cross-Site Scripting (XSS) via email notification templates.\nThe flaw exists because the plugin fails to sanitize or escape user-supplied form-field values before embedding them directly into the HTML body of automated emails dispatched to administrators and form submitters.\nAs an unauthenticated attack vector, an external actor can craft malicious input containing arbitrary HTML or JavaScript markup within a form submission.\nWhen the plugin processes this submission and generates the notification email, the malicious payload is rendered by the recipient's email client.\nThis creates a significant risk, as it allows attackers to bypass security boundaries, potentially leading to unauthorized script execution in the context of the recipient's email environment, session hijacking, or the distribution of phishing content disguised as legitimate site communications.\nThe impact is severe given that these notifications are typically viewed by privileged administrative users, thereby elevating the potential for unauthorized administrative actions or credential harvesting.",
"technicalDetails": "The root cause of this vulnerability lies in the insecure handling of user-controllable data during the email generation process in the MetForm plugin. The application accepts input via form fields but fails to implement adequate sanitization (e.g., stripping dangerous tags) or output encoding (e.g., converting special characters to HTML entities) before the data is integrated into the notification template's HTML body.\nThe vulnerability manifests because the plugin essentially reflects unsanitized input into the email structure. When an end-user submits a form, the plugin captures the field values and concatenates them into the notification email body. If the application does not validate that the input conforms to expected formats and instead treats the raw input as trusted content, an attacker can inject malicious markup.\nThe attack flow follows a structured sequence: 1) The attacker identifies a publicly accessible form powered by the MetForm plugin. 2) The attacker submits the form, populating fields with a malicious payload consisting of HTML tags such as <script>, <iframe>, or <img> with event handlers (e.g., onerror). 3) The server receives this request and stores the malicious payload in the plugin's data processing pipeline. 4) The plugin triggers an automated email notification process to the administrator or the submitter, dynamically populating the email body with the raw, attacker-supplied data. 5) The recipient opens the email using an HTML-capable email client. 6) The email client parses and executes the injected markup, resulting in the execution of arbitrary JavaScript within the context of the email application or triggering external requests.\nBecause this process requires no authentication, any visitor to the website can trigger the vulnerability. The payload behavior is limited only by the recipient's email client's security policies regarding the execution of active content; however, modern techniques allow for the bypassing of many basic filters through obfuscated HTML tags or cross-origin requests.\nThe post-exploitation impact includes the potential for session token theft if the email client renders the JavaScript in a way that allows access to browser cookies, or more commonly, the deployment of sophisticated phishing campaigns. Since the email appears to originate from the legitimate website, the likelihood of a recipient interacting with the malicious payload is significantly higher, potentially leading to total site compromise if an administrator is successfully phished or tricked into performing actions that grant the attacker unauthorized privileges."
}