CVE-2026-103339: WordPress Metform plugin <= 4.3.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet Metform metform allows Stored XSS.This issue affects Metform: from n/a through 4.3.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Metform pluginto a version that resolves this vulnerability.Fixed in 4.3.1
Event History
Frequently Asked Questions
Does exploitation require an authenticated account?
Yes. The attack vector indicates low privileges are required, so an unauthenticated attacker is not represented by the provided severity data.
Is user interaction needed for the attack to have an effect?
Yes. The severity vector indicates that user interaction is required. Because this is stored XSS, the injected content may affect users who later interact with the page where it is rendered.
Which installations should be considered affected?
Metform versions through 4.3.0 are affected. Administrators can identify potentially affected sites by checking whether the installed Metform version is 4.3.0 or earlier.
What impact can successful exploitation have?
The provided severity data rates confidentiality, integrity, and availability impact as low, with scope changed. The vulnerability is classified as stored cross-site scripting.