WordPress Plugin Vulnerabilities

MetForm < 4.1.9 - Unauthenticated Email Header Injection via Notification Reply-To

Description

The plugin does not properly neutralize newline characters in user-submitted values that are placed into notification email headers, allowing unauthenticated attackers to inject additional email headers, such as Bcc, into the emails the site sends when a submitted field value is configured to populate a header.

Proof of Concept

Affects Plugins

Fixed in 4.1.9

References

Classification

Type
INJECTION
OWASP top 10

Miscellaneous

Original Researcher
Artus KG
Submitter
Artus KG
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-09-09 (about 2 days ago)
Added
2026-09-09 (about 1 day ago)
Last Updated
2026-09-09 (about 1 day ago)

Other