Junglewise Threat Intelligence

CVE-2026-24611: WPMet MetForm Pro broken access control

CVE-2026-24611 · Severity: critical · CVSS 9.1 · Published 2026-06-17

Vendors: Wpmet.

Executive brief

MetForm Pro is a WordPress plugin used to create professional contact forms and data collection tools. A security flaw allows unauthorized individuals to bypass access controls, potentially leading to the exposure of sensitive user data or disruption of website operations. Because no official fix is currently available, websites using this plugin are at high risk of automated attacks.

Technical details

A broken access control vulnerability exists in the MetForm Pro plugin for WordPress (versions 3.9.1 and below) due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw to perform actions that should be restricted to higher-privileged users. According to the CVSS vector, the impact includes high confidentiality loss and high availability impact. As of the advisory date, no official patch has been released by the vendor, though third-party mitigation rules may be available.

Affected products

  • WPMet MetForm Pro <= 3.9.1

Timeline

  • 2025-12-13: other: Vulnerability reported by researcher Phat RiO
  • 2026-03-12: advisory: Initial disclosure by Patchstack
  • 2026-06-17: disclosed: CVE published to NVD

References

Related threats