CVE-2026-86832: MetForm < 4.3.1 - Unauthenticated Form Entry Data Disclosure via REST API
Published Oct 3, 2026
·Updated
The MetForm WordPress plugin before 4.3.1 does not properly restrict access to form submission data, allowing unauthenticated attackers to view submitter information through the REST API.
Affected Software
1 affected component
Wpmet Metform<4.3.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MetFormto a version that resolves this vulnerability.Fixed in 4.3.1
Event History
Oct 3, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can access the exposed submission data?
Unauthenticated attackers can view submitter information through the plugin's REST API. No account or prior authentication is required.
2
Which installations are affected?
Wpmet MetForm versions before 4.3.1 are affected. The available information does not identify any configuration prerequisite.
3
How can I determine whether my site is at risk?
Check the installed MetForm plugin version. Sites running a version earlier than 4.3.1 should be treated as vulnerable.