rootpwn

low · CVSS v3 3.7 · EPSS 0.00145

CVE-2026-86834

The MetForm WordPress plugin (v<4.3.1) writes a debug file to the web root whenever HubSpot Forms integration is enabled. The file is access

Overview

The MetForm WordPress plugin (v<4.3.1) writes a debug file to the web root whenever HubSpot Forms integration is enabled. The file is accessible to unauthenticated users, exposing upstream API response data, correlation IDs, and cookies. This can aid attackers in gathering sensitive information about the site’s integration.

Description

The MetForm WordPress plugin before 4.3.1 does not properly restrict access to a debug file it writes to the web root on every form submission when its HubSpot Forms integration is enabled, allowing unauthenticated attackers to read upstream API response data, including correlation identifiers and cookies.

Impact

Confidentiality: attackers can read debug data that may reveal internal correlation identifiers and session cookies, potentially enabling session hijacking or further reconnaissance. Integrity: no direct modification, but exposure of data could assist in planning. Availability: no impact. Defenders: site administrators and security teams.

Remediation

Upgrade MetForm to version 4.3.1 or later. If upgrade not possible, disable the HubSpot Forms integration or remove the debug file from the web root and restrict its permissions. Monitor for any exposed debug files and ensure web server denies access to .php or .txt files in the root.

Risk context

Severity is low with a CVSS v3 score of 3.7 and an EPSS of 0.00145, indicating a very low probability of exploitation. Nonetheless, the exposed data can aid attackers in reconnaissance, so timely patching is recommended.

Affected products

  • MetForm WordPress plugin

Scores

Severity
low
CVSS v2
2.6
CVSS v3
3.7
CVSS v4
—
EPSS
0.00145

WordPress MetForm debug-file information-disclosure low-severity EPSS cve-2026-86834

← All CVEs