CVE-2026-86833
MEDIUM
NVD
CVSS Score
5.4
Severity
MEDIUM
Published
Oct 07, 2026
Vendor
unknown
Description
The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its email notifications, allowing unauthenticated attackers to inject arbitrary markup into the administrator and submitter notification emails the site sends.