This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis →
Q1What is this vulnerability? (Essence + Consequences)
🚨 **Essence**: Improper Access Control in `action.php` allows unauthenticated data leakage. 💥 **Consequences**: Attackers can steal sensitive API keys (PayPal, Stripe, Mailchimp, etc.) and secrets.…
🛡️ **Root Cause**: CWE-862 (Missing Authorization). 🐛 **Flaw**: The file `~/core/forms/action.php` lacks proper access checks. 🔓 **Result**: No authentication required to access sensitive configuration data.
Q3Who is affected? (Versions/Components)
👥 **Vendor**: roxnor. 📦 **Product**: MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor. 📅 **Affected Versions**: Metform <= 2.1.3. 🌐 **Platform**: WordPress sites using this specific plugin.
Q4What can hackers do? (Privileges/Data)
🕵️ **Privileges**: Unauthenticated (No login needed). 🔑 **Data Exposed**: All API keys and secrets for integrated services (PayPal, Stripe, Hubspot, HelpScout, reCAPTCHA, etc.).…
🔧 **Fix**: Update MetForm plugin to version > 2.1.3. 📝 **Patch**: Official changeset `2711944` in `core/forms/action.php` addresses the access control.…
🔥 **Priority**: CRITICAL. ⏱️ **Urgency**: HIGH. 💸 **Risk**: Direct financial impact due to payment gateway keys (Stripe/PayPal) exposure. 🚀 **Action**: Patch immediately. Do not wait for next maintenance window.