PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14206 HT CVE debrief

The HT Contact Form WordPress plugin before 2.9.3 has a vulnerability that allows unauthenticated users to access personal data stored in form drafts. This issue arises from the plugin's lack of authorization checks on endpoints returning saved form drafts. The vulnerability can lead to privacy breaches, as sensitive information such as names, emails, phone numbers, and addresses stored in form drafts can be accessed by unauthorized users. Users of the HT Contact Form WordPress plugin, especially those with sensitive information in form drafts, should be aware of this vulnerability. Operators, platform administrators, and security teams need to assess their exposure and take appropriate actions to protect their environments. Vulnerability management and security teams should prioritize patching and monitoring for this issue. To verify and mitigate this vulnerability, defenders should check plugin versions, review form draft access controls, and monitor for unauthorized access attempts.

Vendor
HT
Product
HT Contact Form
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-10
Original CVE updated
2026-08-10
Advisory published
2026-08-10
Advisory updated
2026-08-10

Who should care

Users of the HT Contact Form WordPress plugin, especially those with sensitive information in form drafts, should be aware of this vulnerability. Operators, platform administrators, and security teams need to assess their exposure and take appropriate actions to protect their environments. Vulnerability management and security teams should prioritize patching and monitoring for this issue. Security teams should also review compensating controls for exposed systems and track exceptions, retest remediated assets, and close the item only after evidence is documented.

Technical summary

The HT Contact Form WordPress plugin before 2.9.3 lacks authorization checks on endpoints returning saved form drafts. Unauthenticated users can access personal data (name, email, phone, address) stored in form drafts. This issue allows unauthorized users to read sensitive information stored in form drafts, potentially leading to privacy breaches. The vulnerability can be mitigated by updating to plugin version 2.9.3 or later and monitoring for unauthorized access attempts.

Defensive priority

Unauthenticated users can access personal data stored in form drafts. Verify and restrict access to form endpoints.

Recommended defensive actions

  • Verify and restrict access to form endpoints
  • Update to plugin version 2.9.3 or later
  • Monitor for unauthorized access attempts
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions, retest remediated assets
  • Confirm whether affected product deployments exist in managed environments

Evidence notes

The HT Contact Form WordPress plugin before 2.9.3 does not perform authorization checks on saved form draft endpoints. Limited information available. To verify, defenders should check plugin versions, review form draft access controls, and monitor for unauthorized access attempts. The vulnerability allows unauthenticated users to access personal data stored in form drafts, potentially leading to privacy breaches. Defenders should verify the plugin version, review form draft access controls, and monitor for unauthorized access attempts to protect their environments.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T07:16:46.710Z and has not been modified since then.