SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-86813

MEDIUM · CVSS 4.8 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The MetForm WordPress plugin prior to version 4.1.9 is vulnerable to header injection due to improper handling of newline characters in user-submitted values, enabling unauthenticated attackers to manipulate email headers, including adding Bcc fields. This could lead to unauthorized information disclosure through email notifications. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation risks.

CVE
CVE-2026-86813
Severity
MEDIUM
CVSS
4.8
EPSS
0.15%
WordPress

Original NVD Description

The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user-submitted values that are placed into notification email headers, allowing unauthenticated attackers to inject additional email headers, such as Bcc, into the emails the site sends when a submitted field value is configured to populate a header.