Skip to main content
Vulnerability Database/CVE-2026-86832

CVE-2026-86832: MetForm WordPress Information Disclosure

CVE-2026-86832 is an information disclosure vulnerability in the MetForm WordPress plugin that exposes form submission data to unauthenticated attackers. This article covers technical details, affected versions, and steps to secure your installation.

Published:

CVE-2026-86832 Overview

CVE-2026-86832 affects the MetForm WordPress plugin in versions prior to 4.3.1. The plugin fails to properly restrict access to form submission data exposed through its REST API endpoints. Unauthenticated attackers can query these endpoints to retrieve information submitted by form users without any authentication credentials. The flaw is classified as [CWE-200] Information Exposure. Public exploitation has not been confirmed, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Critical Impact

Unauthenticated remote attackers can read submitter data collected by MetForm forms, exposing personally identifiable information (PII) and other confidential fields entered into site forms.

Affected Products

  • MetForm WordPress plugin versions prior to 4.3.1
  • WordPress sites exposing the MetForm REST API endpoint
  • Any environment using MetForm to collect contact, registration, or lead-capture submissions

Discovery Timeline

  • 2026-10-03 - CVE-2026-86832 published to NVD
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-86832

Vulnerability Analysis

MetForm is a form-builder plugin for WordPress that stores user submissions in the database and exposes administrative data through REST API routes. The vulnerable versions register one or more REST endpoints that return submission records without validating the identity or capabilities of the requester. Any client that can reach the WordPress site over the network can issue a request and receive submitter data in the response.

The vulnerability is a broken access control flaw rather than a code execution issue. Impact is limited to confidentiality of stored form submissions. Depending on the forms deployed, exposed data may include names, email addresses, phone numbers, messages, or other fields the site operator configured. Integrity and availability of the WordPress site are not affected.

See the WPScan Vulnerability Report for the public disclosure record.

Root Cause

The REST API handler responsible for returning form entries does not enforce a permission_callback that restricts access to authenticated administrators. In WordPress REST API design, each route must declare a permission callback that validates user capabilities. When this callback is missing or returns true unconditionally, the endpoint is reachable by anonymous clients. MetForm versions before 4.3.1 ship with this misconfiguration on the submission-retrieval route.

Attack Vector

Exploitation requires only network access to the target WordPress site. An attacker sends an HTTP GET request to the vulnerable MetForm REST endpoint and parses the JSON response. No user interaction, authentication, or elevated privilege is required. The attack can be automated at scale against WordPress sites that expose the plugin.

The vulnerability manifests at the REST route registration layer. No verified public proof-of-concept code is published at this time. See the WPScan advisory above for additional technical context.

Detection Methods for CVE-2026-86832

Indicators of Compromise

  • Unauthenticated HTTP GET requests to /wp-json/metform/ REST API routes from unfamiliar source addresses
  • Repeated enumeration of form IDs through sequential REST API queries
  • Large JSON responses returned from MetForm endpoints to anonymous clients
  • Spikes in outbound bandwidth from the WordPress host correlated with REST API traffic

Detection Strategies

  • Review WordPress access logs for requests to /wp-json/metform/* that lack an authenticated session cookie or nonce
  • Correlate web server logs with WAF alerts to identify scripted enumeration of REST endpoints
  • Baseline normal REST API traffic volumes and alert on deviations tied to MetForm routes

Monitoring Recommendations

  • Enable verbose logging on the WordPress REST API and forward events to a centralized SIEM for retention and analysis
  • Monitor for the MetForm plugin version string in asset inventory and flag hosts running versions below 4.3.1
  • Alert on anonymous responses to MetForm endpoints that return HTTP 200 with JSON payloads larger than a defined threshold

How to Mitigate CVE-2026-86832

Immediate Actions Required

  • Upgrade the MetForm plugin to version 4.3.1 or later on all WordPress sites
  • Audit existing form submissions to identify data that may have been exposed
  • Notify affected form submitters if investigation confirms unauthorized access to PII
  • Rotate any credentials, tokens, or secrets that users may have submitted through MetForm forms

Patch Information

The vendor addressed the issue in MetForm 4.3.1 by adding proper permission checks to the REST API routes that return submission data. Site administrators should apply the update through the WordPress plugin dashboard or by replacing the plugin files manually. Verify the installed version after update by checking the Plugins page in wp-admin.

Workarounds

  • Deactivate the MetForm plugin until the patched version can be installed
  • Restrict access to /wp-json/metform/ routes at the web server or WAF layer, allowing only authenticated administrative IPs
  • Disable the WordPress REST API for unauthenticated users where business requirements permit
  • Remove historical form submission data that is no longer required to reduce exposure
bash
# Example nginx configuration to block unauthenticated access to MetForm REST routes
location ~ ^/wp-json/metform/ {
    allow 10.0.0.0/8;
    deny all;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.