The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.
Metrics
Affected Vendors & Products
References
History
Mon, 10 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts. | |
| Title | HT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data Disclosure | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-10T06:00:15.077Z
Reserved: 2026-06-30T09:37:44.039Z
Link: CVE-2026-14206
No data.
No data.
No data.
OpenCVE Enrichment
No data.