MEDIUM (6.0)
    Plugin

    Improper Input Validation in MetForm Pro Plugin Allows Payment Manipulation

    Published Date: 4/15/2026
    CVE ID: CVE-2026-1782

    Summary

    The MetForm Pro plugin for WordPress suffers from improper input validation in versions up to and including 3.9.7, enabling attackers to manipulate payments. The issue arises from the plugin's failure to validate user-submitted calculation field values against configured form prices in its payment integrations.

    Vulnerability Details

    The vulnerability in the MetForm Pro plugin stems from unvalidated user input in the 'mf-calculation' field during form submissions involving payment processing through Stripe or PayPal. The plugin trusts the submitted value without recomputing or validating it against the actual price set in the form configuration. This flaw can be exploited by unauthenticated attackers who can alter the payment amount in the transaction request, leading to potential financial losses for site owners who use the form for processing payments. This vulnerability is particularly concerning for any site that relies on financial transactions via these forms, as it undermines the integrity of pricing mechanisms. The trust placed in user-submitted values without verification is a common security oversight that can lead to severe exploitation if not adequately addressed.

    Recommendations

    Site administrators should immediately disable MetForm Pro plugin's payment functionalities until a patch is released. Review current forms' configurations to ensure there is no unnecessary exposure, and limit usage of calculation fields where possible. As a preventive measure, employ a web application firewall (WAF) to detect and block malicious form submission attempts.

    Available Fixes

    Last Updated: 4/16/2026
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More