Sceawere
Vulnerability Detail
CVE-2026-86834UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MetForm Unauthenticated Debug File Access
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.7
- Creation Date
- 13h ago
- Vendor
- Unknown
- Product
- MetForm
- Attack Type
- CWE-200 Information Exposure
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
The MetForm WordPress plugin before 4.3.1 does not properly restrict access to a debug file it writes to the web root on every form submission when its HubSpot Forms integration is enabled, allowing unauthenticated attackers to read upstream API response data, including correlation identifiers and cookies.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.7",
"pubDate": "2026-10-03T06:16:44.013Z",
"pubdate": "2026-10-03T06:16:44.013Z",
"executiveSummary": "The MetForm WordPress plugin, specifically versions prior to 4.3.1, contains an Improper Access Control vulnerability that exposes sensitive debugging information. When the HubSpot Forms integration feature is enabled, the plugin writes a debug file containing upstream API response data directly to the web root. This file is publicly accessible via standard HTTP GET requests, requiring no authentication or specific user privileges. An unauthenticated remote attacker can exploit this flaw to harvest sensitive information, including correlation identifiers and cookies transmitted during the integration process. This exposure presents a significant security risk, as the leaked data may facilitate further attacks, session hijacking, or reconnaissance against the WordPress environment and integrated third-party services. The vulnerability stems from insecure file placement and a failure to implement appropriate directory-level or file-level access restrictions on sensitive diagnostic logs generated by the plugin.",
"technicalDetails": "The vulnerability resides within the MetForm plugin's HubSpot Forms integration module. Upon each form submission, the plugin generates a debug log file stored in the web-accessible root directory of the WordPress installation. The root cause is a lack of server-side access control mechanisms or restrictive file permissions applied to these generated log files, effectively bypassing the security boundary intended to protect internal diagnostic data.\nThe attack flow commences when the HubSpot integration is active. As users interact with MetForm-powered forms, the plugin executes backend logic to communicate with the HubSpot API. During these transactions, the plugin writes verbose debugging output to a file within the web root. Because the file is located within the public web directory, it is served directly by the web server (e.g., Apache or Nginx) when requested by a client. An attacker does not require any specialized privileges or credentials to access this information; they only need to discover the file path, which follows a predictable naming convention or structure.\nUpon successful access, the attacker can retrieve the contents of the debug file. This content includes sensitive information regarding the API exchange, such as correlation identifiers, which can be used to track specific requests, and, critically, cookies or session tokens passed during the API communication process. The impact of this exposure is severe, as the leaked credentials and session identifiers can be used to impersonate administrative or user actions, or to gain insight into the internal configuration of the HubSpot integration.\nThis vulnerability is classified as an Improper Access Control issue. It is present in all versions of the MetForm plugin prior to 4.3.1. The attack is fully network-accessible and requires no prior authentication, making it a low-complexity exploit that can be automated by malicious actors scanning for common plugin vulnerabilities. The post-exploitation impact includes unauthorized information disclosure and the potential for secondary attacks leveraging the retrieved session data to gain further access to the WordPress application or associated SaaS platforms."
}