Metform
Metform PRO: vulnerabilidades y CVE
Metform PRO tiene 4 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE4
Últimos 12 meses4
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-24611 | Crítica (9.1) | 0.44% | — | 17 jun 2026 | Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions. |
| CVE-2026-24610 | Media (4.3) | 0.24% | — | 17 jun 2026 | Subscriber Broken Access Control in MetForm Pro <= 3.9.1 versions. |
| CVE-2026-1782 | Media (5.3) | 0.27% | — | 15 abr 2026 | The MetForm Pro plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 3.9.7 This is due to the payment integrations (Stripe/PayPal) trusting a user-submitted calculation… |
| CVE-2026-1261 | Alta (7.2) | 0.31% | — | 10 mar 2026 | The MetForm Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Quiz feature in all versions up to, and including, 3.9.6 due to insufficient input sanitization and output escaping. This makes… |