Junglewise Threat Intelligence

CVE-2026-86813: MetForm email header injection via newline characters

CVE-2026-86813 · Severity: medium · CVSS 4.8 · Published 2026-09-11

Executive brief

MetForm is a popular WordPress plugin for creating contact and submission forms. The plugin fails to properly filter newline characters in user-submitted form data when constructing notification emails, allowing unauthenticated attackers to inject arbitrary email headers (such as Bcc) and cause form submissions to be sent to attacker-controlled email addresses without the site owner's knowledge.

Technical details

The vulnerability is an email header injection flaw (CWE-113) in the MetForm plugin's notification email generation. User-submitted form field values (such as email addresses) are concatenated directly into SMTP header strings without neutralizing newline characters (CRLF). An unauthenticated attacker can craft a form submission containing a newline followed by additional headers (e.g., "Bcc: attacker@example.com") in any field configured to populate an email header. The attack requires the site admin to have configured a form with a field mapped to a notification header and admin email notifications enabled. When the form is submitted, the injected headers are parsed as legitimate SMTP directives, causing the notification email to be silently copied to the attacker's address. The vulnerability is fixed in version 4.1.9.

Affected products

  • MetForm MetForm before 4.1.9

Timeline

  • 2026-09-09: disclosed
  • 2026-09-11: advisory
  • 2026: patched: Fixed in version 4.1.9

References