CVE-2026-86834: MetForm 2.2.1 - 4.3.0 - Unauthenticated Debug File Disclosure via HubSpot Forms Integration
The MetForm WordPress plugin before 4.3.1 does not properly restrict access to a debug file it writes to the web root on every form submission when its HubSpot Forms integration is enabled, allowing unauthenticated attackers to read upstream API response data, including correlation identifiers and cookies.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MetForm WordPress pluginto a version that resolves this vulnerability.Fixed in 4.3.1
Event History
Frequently Asked Questions
Which sites are exposed to this disclosure?
Sites using affected MetForm versions before 4.3.1 are exposed when the HubSpot Forms integration is enabled. The debug file is written on every form submission under that condition.
Does an attacker need an account or form-submission access to retrieve the data?
No. The disclosed debug file can be read by unauthenticated attackers. The available data does not state that an attacker must submit a form themselves.
What information could be exposed?
The file may expose upstream API response data, including correlation identifiers and cookies.
How can I determine whether the issue may already have affected my site?
Verify whether the HubSpot Forms integration is enabled and whether the site runs a MetForm version earlier than 4.3.1. Review the web root for the debug file created by MetForm and assess whether it was publicly accessible.