CVE-2026-86832
The MetForm WordPress plugin before 4.3.1 does not properly restrict access to form submission data, allowing unauthenticated attackers to view submitter information through the REST API.
- Published Oct 3, 2026
- CVSS 5.3 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available