CVE-2026-14206 PUBLISHED

HT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data Disclosure

Assigner: WPScan
Reserved: 30.06.2026 Published: 10.08.2026 Updated: 10.08.2026

The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.

Product Status

Vendor Unknown
Product HT Contact Form
Versions Default: unaffected
  • affected from 0 to 2.9.3 (excl.)

Credits

  • Mustafa Ahmed finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE