---
id: CVE-2026-86832
title: >-
  The MetForm  WordPress plugin before 4.3.1 does not properly restrict access
  to form submission data, allowing unauthenticated attackers to view submitter
  information through the REST API.
summary: >-
  The MetForm  WordPress plugin before 4.3.1 does not properly restrict access
  to form submission data, allowing unauthenticated attackers to view submitter
  information through the REST API.
severity: none
cwe:
  - CWE-200
product: MetForm
affected:
  - MetForm < 4.3.1
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T06:16:43.763'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86832'
references:
  - url: 'https://wpscan.com/vulnerability/d73e4c95-471b-4f22-97a0-b6a59f187bcd/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-03T06:39:57.564Z'
---

## Overview

The MetForm  WordPress plugin before 4.3.1 does not properly restrict access to form submission data, allowing unauthenticated attackers to view submitter information through the REST API.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
