PatchSiren cyber security CVE debrief
CVE-2026-14206 HT CVE debrief
The HT Contact Form WordPress plugin before 2.9.3 has a vulnerability that allows unauthenticated users to access personal data stored in form drafts. This issue arises from the plugin's lack of authorization checks on endpoints returning saved form drafts. The vulnerability can lead to privacy breaches, as sensitive information such as names, emails, phone numbers, and addresses stored in form drafts can be accessed by unauthorized users. Users of the HT Contact Form WordPress plugin, especially those with sensitive information in form drafts, should be aware of this vulnerability. Operators, platform administrators, and security teams need to assess their exposure and take appropriate actions to protect their environments. Vulnerability management and security teams should prioritize patching and monitoring for this issue. To verify and mitigate this vulnerability, defenders should check plugin versions, review form draft access controls, and monitor for unauthorized access attempts.
- Vendor
- HT
- Product
- HT Contact Form
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-08-10
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-08-10
Who should care
Users of the HT Contact Form WordPress plugin, especially those with sensitive information in form drafts, should be aware of this vulnerability. Operators, platform administrators, and security teams need to assess their exposure and take appropriate actions to protect their environments. Vulnerability management and security teams should prioritize patching and monitoring for this issue. Security teams should also review compensating controls for exposed systems and track exceptions, retest remediated assets, and close the item only after evidence is documented.
Technical summary
The HT Contact Form WordPress plugin before 2.9.3 lacks authorization checks on endpoints returning saved form drafts. Unauthenticated users can access personal data (name, email, phone, address) stored in form drafts. This issue allows unauthorized users to read sensitive information stored in form drafts, potentially leading to privacy breaches. The vulnerability can be mitigated by updating to plugin version 2.9.3 or later and monitoring for unauthorized access attempts.
Defensive priority
Unauthenticated users can access personal data stored in form drafts. Verify and restrict access to form endpoints.
Recommended defensive actions
- Verify and restrict access to form endpoints
- Update to plugin version 2.9.3 or later
- Monitor for unauthorized access attempts
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets
- Track exceptions, retest remediated assets
- Confirm whether affected product deployments exist in managed environments
Evidence notes
The HT Contact Form WordPress plugin before 2.9.3 does not perform authorization checks on saved form draft endpoints. Limited information available. To verify, defenders should check plugin versions, review form draft access controls, and monitor for unauthorized access attempts. The vulnerability allows unauthenticated users to access personal data stored in form drafts, potentially leading to privacy breaches. Defenders should verify the plugin version, review form draft access controls, and monitor for unauthorized access attempts to protect their environments.
Official resources
-
CVE-2026-14206 CVE record
CVE.org
-
CVE-2026-14206 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T07:16:46.710Z and has not been modified since then.