CVE-2026-1782: MetForm Pro <= 3.9.7 - Unauthenticated Payment Amount Manipulation via 'mf-calculation'
The MetForm Pro plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 3.9.7 This is due to the payment integrations (Stripe/PayPal) trusting a user-submitted calculation field value without recomputing or validating it against the configured form price. This makes it possible for unauthenticated attackers to manipulate the payment amount via the 'mf-calculation' field in the form submission REST request granted there exists a specific form with this particular configuration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1782?
CVE-2026-1782 is considered a high severity vulnerability due to its potential impact on financial transactions.
How do I fix CVE-2026-1782?
To fix CVE-2026-1782, update the MetForm Pro plugin to version 3.9.8 or later.
What kind of vulnerability is CVE-2026-1782?
CVE-2026-1782 is an Improper Input Validation vulnerability affecting the MetForm Pro plugin.
What versions of MetForm Pro are affected by CVE-2026-1782?
CVE-2026-1782 affects all versions of MetForm Pro up to and including 3.9.7.
What are the potential consequences of CVE-2026-1782?
The potential consequences of CVE-2026-1782 include unauthorized manipulation of payment amounts by unauthenticated users.