S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-1442 Scanner

CVE-2022-1442 scanner - Information Disclosure vulnerability in Metform plugin for Wordpress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-1442
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unauthenticated attacker to view all API keys and secrets of integrated third-party APIs like that of PayPal, Stripe, Mailchimp, Hubspot, HelpScout, reCAPTCHA and many more, in versions up to and including 2.1.3.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementorby roxnor
0
Updated Aug 22, 2026View on NVD →
Detail

Metform is a widely used plugin for WordPress for creating contact forms and quizzes. It is a user-friendly tool that lets website owners easily create forms in minutes without any coding or technical knowledge. This plugin is integrated with various third-party APIs like PayPal, Stripe, Mailchimp, Hubspot, HelpScout, reCAPTCHA, and more.

However, recently a vulnerability has been discovered in the Metform plugin for WordPress. The vulnerability code, CVE-2022-1442, allows an attacker to view all API keys and secrets of the integrated third-party APIs, even without being authenticated. The attacker can easily gain access to sensitive information due to improper access controls in the ~/core/forms/action.php file, present in all versions up to and including 2.1.3.

The exploitation of this vulnerability can lead to a massive data breach, putting all sensitive information at risk of being leaked. Attackers can get their hands on payment transaction details, email lists, customer information, and other confidential data. This vulnerability gives attackers direct access to the keys, allowing them to perform malicious activities like initiating unauthorized transactions, phishing scams, and more.

The pro features of s4e.io platform offer an easy and quick solution to learn about vulnerabilities in digital assets. It provides a comprehensive report on vulnerabilities in digital assets, including the status, type, severity, and remediation steps. The platform offers a user-friendly interface and recommends actions to be taken to prevent vulnerabilities. Users can rely on the pro features of the s4e.io platform to ensure their digital assets are always secured and protected from any potential vulnerabilities.

 

REFERENCES

Solution Advice

To protect your website from this vulnerability, you can take the following precautions:

  • Update your Metform plugin to the latest version immediately.
  • Restrict access to the ~/core/forms/action.php file.
  • Use strong passwords for API keys and secrets.
  • Implement IP restrictions to block unauthorized access.
  • Use any security plugin available to prevent any unauthorized access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.