CVE-2026-1261: MetForm Pro <= 3.9.6 - Unauthenticated Stored Cross-Site Scripting
The MetForm Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Quiz feature in all versions up to, and including, 3.9.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1261?
CVE-2026-1261 has a critical severity rating due to its potential for unauthenticated stored cross-site scripting.
How do I fix CVE-2026-1261?
To fix CVE-2026-1261, update the MetForm Pro plugin to version 3.9.7 or later.
Which versions of MetForm Pro are affected by CVE-2026-1261?
CVE-2026-1261 affects all versions of MetForm Pro up to and including 3.9.6.
What type of vulnerability is CVE-2026-1261?
CVE-2026-1261 is classified as an unauthenticated stored cross-site scripting vulnerability.
How does CVE-2026-1261 impact WordPress sites?
CVE-2026-1261 can allow attackers to execute malicious scripts on the client side, leading to potential data theft or site compromise.