CVE · Medium

CVE-2026-24610 — MetForm Pro [metform-pro] < 3.9.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-24610 MetForm Pro [metform-pro] < 3.9.9 Missing Authorization Medium 4.3 < 3.9.9 3.9.9 2026-06-17

CVE-2026-24610

A vulnerability has been identified in MetForm Pro plugin versions prior to 3.9.2, where an unauthorized user can potentially gain access to subscriber-only content due to inadequate access control measures. This issue stems from a flaw in the plugin's security framework that allows bypass of intended restrictions. As a result, subscribers' sensitive information may be compromised.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.