CVE-2023-50903: Wpmet Metform Elementor Contact Form Builder

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Missing Authorization vulnerability in Roxnor Metform metform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Metform: from n/a through <= 3.4.0.

Affected products

  • Wpmet Metform Elementor Contact Form Builder: before 3.4.1 (fixed in 3.4.1)

Published 2024-12-09. Last modified 2026-06-17.