CVE-2026-1261General

LOWCVSS 7.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The MetForm Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Quiz feature in all versions up to, and including, 3.9.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-19)
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-19: 2Technical Details · 2026-03-10: 1Technical Details · 2026-03-19: 203-1003-1103-19
Signal classification2 categories
General
250.0%
Disclosure
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-101
General1
2026-03-111
General1
2026-03-192
Disclosure2
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-1261 The MetForm Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Quiz feature in all versions up to, and including, 3.9.6 due to insufficient i… https://www.cve.org/CVERecord?id=CVE-2026-1261 ----- Traducción: CVE-2026-1261 El … http://infoflow.cloud`

    Post summary

    CVE-2026-1261 is a stored XSS vulnerability in MetForm Pro's Quiz feature up to version 3.9.6; the tweet reports the vulnerability announcement but provides no PoC, exploit, patch, or exploitation evidence.

    0000035
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1261 The MetForm Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Quiz feature in all versions up to, and including, 3.9.6 due to insufficient i… https://www.cve.org/CVERecord?id=CVE-2026-1261

    Post summary

    A stored cross‑site scripting vulnerability (CVE‑2026‑1261) was disclosed in the MetForm Pro WordPress plugin, impacting the Quiz feature in all versions up to 3.9.6.

    00000223
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-1261 - Wpmet - MetForm Pro - https://www.redpacketsecurity.com/cve-alert-cve-2026-1261-wpmet-metform-pro/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-1261 #wpmet #metform-pro

    Post summary

    A brief tweet alerts a CVE‑2026‑1261 vulnerability in MetForm Pro but supplies no technical, exploit, or mitigation details.

    0000055
    3.5K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-1261 - MetForm Pro for WordPress Stored Cross-Site Scripting Intel Report: https://ift.tt/MXGQUum

    Post summary

    An alert notes CVE-2026-1261 as a stored XSS flaw in MetForm Pro for WordPress, providing an Intel report link but no PoC, exploitation details, or patch information.

    0000035
    345 followersView on X

Explore more