CVE · High

CVE-2022-1442 — MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor [metform] < 3.2.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-1442 MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor [metform] < 3.2.0 Missing Authorization High 7.5 < 3.2.0 3.2.0 2022-04-23

CVE-2022-1442

The Metform plugin for WordPress versions 2.1.3 and earlier contains an access control vulnerability in the ~/core/forms/action.php file that allows unauthenticated attackers to retrieve sensitive API credentials. An attacker can exploit this flaw to view API keys and secrets for integrated third-party services including PayPal, Stripe, Mailchimp, Hubspot, HelpScout, and reCAPTCHA. This issue was fixed in version 3.2.0.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.