WordPress 插件 MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor 在 4.1.8 及以下所有版本中存在存储型跨站脚本(Stored XSS)漏洞。该漏洞源于 'mf_form_id' 小部件设置中缺乏充分的输入清理和输出转义。这使得具备贡献者(Contributor)及以上权限的认证攻击者能够在网页中注入任意的 Web 脚本,每当用户访问被注入的页面时,这些脚本便会执行。 该有效载荷能够绕过 Elemento
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| roxnor | MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor | ≤ 4.1.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| roxnor | MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor | 0 ~ 4.1.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75971 | 7.2 HIGH | ShopEngine Elementor WooCommerce Builder Addon <= 4.9.4 - Authenticated (Shop Manager+) Pr |
| CVE-2026-76063 | 6.4 MEDIUM | FundEngine <= 1.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wfp_fea |
| CVE-2026-75930 | 4.3 MEDIUM | FundEngine <= 1.8.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post |
No comments yet