Executive brief
MetForm Pro is a WordPress plugin used to create professional contact forms and data entry tools. A security flaw allows users with basic 'Subscriber' accounts to perform actions they should not be authorized to access. This could lead to unauthorized changes to form settings or data, though it does not typically allow for full site takeover or data theft.
Technical details
A broken access control vulnerability exists in MetForm Pro versions up to and including 3.9.1 due to missing authorization checks (CWE-862). An authenticated attacker with Subscriber-level privileges can exploit this flaw over the network without user interaction. The vulnerability allows for unauthorized modification of data or settings within the plugin's scope. As of the advisory date, no official patch has been released, and users are advised to monitor for updates from WPMet.
Affected products
- WPMet MetForm Pro <= 3.9.1
Timeline
- 2025-12-13: other: Vulnerability reported by researcher Phat RiO
- 2026-01-12: advisory: Initial disclosure by Patchstack
- 2026-06-17: disclosed: CVE published to NVD