First published: Thu Mar 27 2025(Updated: )
Server-Side Request Forgery (SSRF) vulnerability in XpeedStudio Metform allows Server Side Request Forgery. This issue affects Metform: from n/a through 3.9.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
XpeedStudio Metform | <=3.9.2 | |
MetForm Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | <=3.9.2 |
Update the WordPress Metform Elementor Contact Form Builder plugin to the latest available version (at least 3.9.3).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-30914 is considered medium due to its potential for Server-Side Request Forgery exploitation.
To fix CVE-2025-30914, upgrade XpeedStudio Metform to version 3.9.3 or later.
CVE-2025-30914 affects XpeedStudio Metform versions up to and including 3.9.2.
CVE-2025-30914 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
CVE-2025-30914 impacts both XpeedStudio Metform and WordPress Metform Elementor Contact Form Builder up to version 3.9.2.