CVE-2026-14206
HT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data Disclosure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.
| Vendor | unknown |
| Product | ht contact form |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown ht contact form
Be the first to know when new unknown vulnerabilities affecting unknown ht contact form are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / HT Contact Form
0 < 2.9.3
References
Credits
Mustafa Ahmed WPScan