PatchSiren cyber security CVE debrief
CVE-2026-14206 HT CVE debrief
The HT Contact Form WordPress plugin before 2.9.3 has a vulnerability that allows unauthenticated users to access personal data stored in form drafts. This issue arises from the plugin's lack of authorization checks on endpoints returning saved form drafts. The vulnerability can lead to privacy breaches, as sensitive information such as names, emails, phone numbers, and addresses stored in form drafts can be accessed by unauthorized users. Users of the HT Contact Form WordPress plugin, especially those with sensitive information in form drafts, should be aware of this vulnerability. Operators, platform administrators, and security teams need to assess their exposure and take appropriate actions to protect their environments. Vulnerability management and security teams should prioritize patching and monitoring for this issue. To verify and mitigate this vulnerability, defenders should check plugin versions, review form draft access controls, and monitor for unauthorized access attempts.
- Vendor
- HT
- Product
- HT Contact Form
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-08-26
Who should care
Users of the HT Contact Form WordPress plugin, especially those with sensitive information in form drafts, should be aware of this vulnerability. Operators, platform administrators, and security teams need to assess their exposure and take appropriate actions to protect their environments. Vulnerability management and security teams should prioritize patching and monitoring for this issue. Security teams should also review compensating controls for exposed systems and track exceptions, retest remediated assets, and close the item only after evidence is documented.
Technical summary
The HT Contact Form WordPress plugin before 2.9.3 lacks authorization checks on endpoints returning saved form drafts. Unauthenticated users can access personal data (name, email, phone, address) stored in form drafts. This issue allows unauthorized users to read sensitive information stored in form drafts, potentially leading to privacy breaches. The vulnerability can be mitigated by updating to plugin version 2.9.3 or later and monitoring for unauthorized access attempts.
Defensive priority
Unauthenticated users can access personal data stored in form drafts. Verify and restrict access to form endpoints.
Recommended defensive actions
- Verify and restrict access to form endpoints
- Update to plugin version 2.9.3 or later
- Monitor for unauthorized access attempts
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions, retest remediated assets
- Confirm whether affected product deployments exist in managed environments
Evidence notes
The HT Contact Form WordPress plugin before 2.9.3 does not perform authorization checks on saved form draft endpoints. Limited information available. To verify, defenders should check plugin versions, review form draft access controls, and monitor for unauthorized access attempts. The vulnerability allows unauthenticated users to access personal data stored in form drafts, potentially leading to privacy breaches. Defenders should verify the plugin version, review form draft access controls, and monitor for unauthorized access attempts to protect their environments.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-14206 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-14206
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-14206 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14206
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/36ae857c-6812-46e0-a0e7-6c868108ef39/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.