Sceawere

Vulnerability Detail

CVE-2026-86834UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

MetForm Unauthenticated Debug File Access

Vulnerability Metadata

Severity
Low
Score / CVSS
3.7
Creation Date
13h ago
Vendor
Unknown
Product
MetForm
Attack Type
CWE-200 Information Exposure
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

The MetForm WordPress plugin before 4.3.1 does not properly restrict access to a debug file it writes to the web root on every form submission when its HubSpot Forms integration is enabled, allowing unauthenticated attackers to read upstream API response data, including correlation identifiers and cookies.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.7",
  "pubDate": "2026-10-03T06:16:44.013Z",
  "pubdate": "2026-10-03T06:16:44.013Z",
  "executiveSummary": "The MetForm WordPress plugin, specifically versions prior to 4.3.1, contains an Improper Access Control vulnerability that exposes sensitive debugging information. When the HubSpot Forms integration feature is enabled, the plugin writes a debug file containing upstream API response data directly to the web root. This file is publicly accessible via standard HTTP GET requests, requiring no authentication or specific user privileges. An unauthenticated remote attacker can exploit this flaw to harvest sensitive information, including correlation identifiers and cookies transmitted during the integration process. This exposure presents a significant security risk, as the leaked data may facilitate further attacks, session hijacking, or reconnaissance against the WordPress environment and integrated third-party services. The vulnerability stems from insecure file placement and a failure to implement appropriate directory-level or file-level access restrictions on sensitive diagnostic logs generated by the plugin.",
  "technicalDetails": "The vulnerability resides within the MetForm plugin's HubSpot Forms integration module. Upon each form submission, the plugin generates a debug log file stored in the web-accessible root directory of the WordPress installation. The root cause is a lack of server-side access control mechanisms or restrictive file permissions applied to these generated log files, effectively bypassing the security boundary intended to protect internal diagnostic data.\nThe attack flow commences when the HubSpot integration is active. As users interact with MetForm-powered forms, the plugin executes backend logic to communicate with the HubSpot API. During these transactions, the plugin writes verbose debugging output to a file within the web root. Because the file is located within the public web directory, it is served directly by the web server (e.g., Apache or Nginx) when requested by a client. An attacker does not require any specialized privileges or credentials to access this information; they only need to discover the file path, which follows a predictable naming convention or structure.\nUpon successful access, the attacker can retrieve the contents of the debug file. This content includes sensitive information regarding the API exchange, such as correlation identifiers, which can be used to track specific requests, and, critically, cookies or session tokens passed during the API communication process. The impact of this exposure is severe, as the leaked credentials and session identifiers can be used to impersonate administrative or user actions, or to gain insight into the internal configuration of the HubSpot integration.\nThis vulnerability is classified as an Improper Access Control issue. It is present in all versions of the MetForm plugin prior to 4.3.1. The attack is fully network-accessible and requires no prior authentication, making it a low-complexity exploit that can be automated by malicious actors scanning for common plugin vulnerabilities. The post-exploitation impact includes unauthorized information disclosure and the potential for secondary attacks leveraging the retrieved session data to gain further access to the WordPress application or associated SaaS platforms."
}
CVE-2026-86834: MetForm Unauthenticated Debug File Access (LOW Severity, CVSS: 3.7) | Sceawere