Executive brief
MetForm is a WordPress plugin for building contact forms, surveys, and quizzes within the Elementor page builder. Authenticated users with contributor-level access can inject malicious JavaScript code into form widget settings that executes when other users view the affected page, potentially enabling account takeover, data theft, or malware delivery.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in the 'mf_form_id' widget setting affecting MetForm versions up to 4.1.8. The root cause is insufficient input sanitization and output escaping in the plugin's form picker component. The attack requires authentication with contributor-level or higher privileges and occurs at page-load time when an attacker-controlled form ID is processed. The payload bypasses Elementor's wp_kses_post filter (which strips HTML tags) by containing no HTML, and exploits MetForm's str_replace transformation that converts script tags into JavaScript template literals, providing an additional injection vector. Patches are available in versions after 4.1.8.
Affected products
- Elementor MetForm up to 4.1.8
Timeline
- 2026-08-25: disclosed