CVE-2023-0688, CVE-2023-0691, CVE-2023-0692, CVE-2023-0693, CVE-2023-0694
The MetForm plugin for Elementor, in versions 3.3.1 and earlier, contains an information disclosure vulnerability in the 'mf_thankyou' shortcode that allows authenticated users with subscriber-level permissions or higher to access sensitive form submission data such as payment status and transaction identification numbers.
Based on public CVE data (MITRE/NVD).