The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.8.8 via the 'handle_file' function. This can allow unauthenticated attackers to extract sensitive data, such as Personally Identifiable Information, from files uploaded by users.
We have discovered 6,786 live websites that are affected by CVE-2024-4266.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 6,786 live websites (20.02% of Metform install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 77 versions ( 91.67% of all versions) |
![]() | 1,958 websites |
![]() | 903 websites |
![]() | 468 websites |
![]() | 352 websites |
![]() | 303 websites |
![]() | 239 websites |
![]() | 201 websites |
![]() | 179 websites |
![]() | 174 websites |
![]() | 141 websites |
.com | 3,071 websites |
.com.br | 356 websites |
.org | 242 websites |
.de | 193 websites |
.co.uk | 171 websites |
.net | 138 websites |
.ru | 137 websites |
.it | 131 websites |
.pl | 101 websites |
.nl | 100 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*******.com | ![]() | **,*** | |
********************.com | ![]() | ***,*** | |
*****************.com | ![]() | ***,*** | |
********.com | ![]() | ***,*** | |
*****************.com | ![]() | ***,*** | |
*************.com | ![]() | ***,*** | |
********.pt | ![]() | ***,*** | |
*********.com | ![]() | ***,*** | |
******.at | ![]() | ***,*** | |
***************.org | ![]() | ***,*** |