Description
WordPress Plugin Metform Elementor Contact Form Builder-Flexible and Design-Friendly Contact Form builder for WordPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change the permalink structure. WordPress Plugin Metform Elementor Contact Form Builder-Flexible and Design-Friendly Contact Form builder for WordPress version 3.3.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.3.2 or latest
References
Related Vulnerabilities
Python Inadequate Encryption Strength Vulnerability (CVE-2014-0224)
Oracle HTTP Server Uncontrolled Resource Consumption Vulnerability (CVE-2022-25313)
ZenCart Other Vulnerability (CVE-2009-4323)
WordPress Plugin Feed Them Gallery Cross-Site Scripting (1.1.8)
Angular Uncontrolled Resource Consumption Vulnerability (CVE-2026-50171)