CVE-2023-1843: Wpmet Metform Elementor Contact Form Builder
Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to unauthorized permalink structure update due to a missing capability check on the permalink_setup function in versions up to, and including, 3.3.0. This makes it possible for unauthenticated attackers to change the permalink structure.
Affected products
- Wpmet Metform Elementor Contact Form Builder: up to and including 3.3.0
Published 2023-06-09. Last modified 2026-06-17.