CVE-2022-1442: Metform Elementor Contact Form Builder <= 2.1.3 - Sensitive Information Disclosure
The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unauthenticated attacker to view all API keys and secrets of integrated third-party APIs like that of PayPal, Stripe, Mailchimp, Hubspot, HelpScout, reCAPTCHA and many more, in versions up to and including 2.1.3.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this Metform WordPress plugin vulnerability?
The vulnerability ID of this Metform WordPress plugin vulnerability is CVE-2022-1442.
What is the severity value of CVE-2022-1442?
The severity value of CVE-2022-1442 is 7.5 (high).
How does this vulnerability in the Metform WordPress plugin occur?
This vulnerability in the Metform WordPress plugin occurs due to improper access control in the ~/core/forms/action.php file, which can be exploited by an unauthenticated attacker.
What can an unauthenticated attacker do with this vulnerability?
An unauthenticated attacker can exploit this vulnerability to view all API keys and secrets of integrated third-party APIs like that of PayPal, Stripe, Mailchimp, etc.
How to fix the vulnerability in the Metform WordPress plugin?
To fix the vulnerability in the Metform WordPress plugin, update to version 2.1.4 or higher.