CVE-2026-86834: Unknown Metform
Low severity, CVSS 3.7. EPSS: 0.2% chance of exploitation in the next 30 days.
The MetForm WordPress plugin before 4.3.1 does not properly restrict access to a debug file it writes to the web root on every form submission when its HubSpot Forms integration is enabled, allowing unauthenticated attackers to read upstream API response data, including correlation identifiers and cookies.
Affected products
- Unknown Metform: from 2.2.1, before 4.3.1 (fixed in 4.3.1)
Published 2026-10-03. Last modified 2026-10-06.