low · CVSS v3 3.7 · EPSS 0.00145
CVE-2026-86834
The MetForm WordPress plugin (v<4.3.1) writes a debug file to the web root whenever HubSpot Forms integration is enabled. The file is access
Overview
The MetForm WordPress plugin (v<4.3.1) writes a debug file to the web root whenever HubSpot Forms integration is enabled. The file is accessible to unauthenticated users, exposing upstream API response data, correlation IDs, and cookies. This can aid attackers in gathering sensitive information about the site’s integration.
Description
The MetForm WordPress plugin before 4.3.1 does not properly restrict access to a debug file it writes to the web root on every form submission when its HubSpot Forms integration is enabled, allowing unauthenticated attackers to read upstream API response data, including correlation identifiers and cookies.
Impact
Confidentiality: attackers can read debug data that may reveal internal correlation identifiers and session cookies, potentially enabling session hijacking or further reconnaissance. Integrity: no direct modification, but exposure of data could assist in planning. Availability: no impact. Defenders: site administrators and security teams.
Remediation
Upgrade MetForm to version 4.3.1 or later. If upgrade not possible, disable the HubSpot Forms integration or remove the debug file from the web root and restrict its permissions. Monitor for any exposed debug files and ensure web server denies access to .php or .txt files in the root.
Risk context
Severity is low with a CVSS v3 score of 3.7 and an EPSS of 0.00145, indicating a very low probability of exploitation. Nonetheless, the exposed data can aid attackers in reconnaissance, so timely patching is recommended.
Affected products
- MetForm WordPress plugin
Scores
- Severity
- low
- CVSS v2
- 2.6
- CVSS v3
- 3.7
- CVSS v4
- —
- EPSS
- 0.00145