The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.
Metrics
Affected Vendors & Products
References
History
Mon, 10 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 10 Aug 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 CWE-284 |
Mon, 10 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts. | |
| Title | HT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data Disclosure | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-10T19:12:12.412Z
Reserved: 2026-06-30T09:37:44.039Z
Link: CVE-2026-14206
Updated: 2026-08-10T19:12:01.013Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-10T08:30:04Z