Stored Cross-Site Scripting Vulnerability in MetForm for WordPress
CVE-2026-18100
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 August 2026
What is CVE-2026-18100?
The MetForm β Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping. Specifically, the vulnerability arises from the 'mf_form_id' widget setting, affecting all versions up to and including 4.1.8. Authenticated attackers with contributor-level access or higher can execute malicious scripts on the pages of users who access the infected content. The attack vector circumvents Elementor's save-time wp_kses_post filter as it cleverly avoids typical HTML tags, leveraging MetForm's internal conversion of script tags into JavaScript template literal expressions for injecting payloads.
Affected Version(s)
MetForm β Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor 0 <= 4.1.8