Email Header Injection in MetForm Plugin for WordPress
CVE-2026-86813
Key Information:
Badges
What is CVE-2026-86813?
The MetForm plugin for WordPress versions prior to 4.1.9 contains a vulnerability that fails to neutralize newline characters in user-submitted values. This flaw permits unauthenticated attackers to inject additional headers, such as Bcc, into outgoing notification emails. This can result in unauthorized exposure of email addresses and compromise the integrity of user communication, which emphasizes the critical need for protecting user input within web applications.
Affected Version(s)
MetForm 0 < 4.1.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved