CVE-2026-86813 Details
Description
The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user-submitted values that are placed into notification email headers, allowing unauthenticated attackers to inject additional email headers, such as Bcc, into the emails the site sends when a submitted field value is configured to populate a header.
A vulnerability exists in the MetForm WordPress plugin in versions prior to 4.1.9. The issue arises because the plugin fails to properly sanitize newline characters in user-submitted values that are used in notification email headers. This flaw allows unauthenticated attackers to inject additional email headers, such as Bcc, into emails sent by the site when a submitted field value is set to populate a header.
Users are advised to update the MetForm WordPress plugin to version 4.1.9 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 11, 2026CISA-ADP
Assessed Sep 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/afda2a26-b965-42cb-85a8-4a4d83ec026e/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-93 | Improper Neutralization of CRLF Sequences ('CRLF Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| MetForm | < 4.1.9 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | CVE Modified | CISA-ADP |
| Sep 11, 2026 | New CVE Received | [email protected] |
Volerion