CyberRota Analysis
AI-GeneratedThe MetForm WordPress plugin prior to version 4.1.9 is vulnerable to header injection due to improper handling of newline characters in user-submitted values, enabling unauthenticated attackers to manipulate email headers, including adding Bcc fields. This could lead to unauthorized information disclosure through email notifications. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation risks.
Original NVD Description
The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user-submitted values that are placed into notification email headers, allowing unauthenticated attackers to inject additional email headers, such as Bcc, into the emails the site sends when a submitted field value is configured to populate a header.