PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14206 HT CVE debrief

The HT Contact Form WordPress plugin before 2.9.3 has a vulnerability that allows unauthenticated users to access personal data stored in form drafts. This issue arises from the plugin's lack of authorization checks on endpoints returning saved form drafts. The vulnerability can lead to privacy breaches, as sensitive information such as names, emails, phone numbers, and addresses stored in form drafts can be accessed by unauthorized users. Users of the HT Contact Form WordPress plugin, especially those with sensitive information in form drafts, should be aware of this vulnerability. Operators, platform administrators, and security teams need to assess their exposure and take appropriate actions to protect their environments. Vulnerability management and security teams should prioritize patching and monitoring for this issue. To verify and mitigate this vulnerability, defenders should check plugin versions, review form draft access controls, and monitor for unauthorized access attempts.

Vendor
HT
Product
HT Contact Form
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-10
Original CVE updated
2026-08-26
Advisory published
2026-08-10
Advisory updated
2026-08-26

Who should care

Users of the HT Contact Form WordPress plugin, especially those with sensitive information in form drafts, should be aware of this vulnerability. Operators, platform administrators, and security teams need to assess their exposure and take appropriate actions to protect their environments. Vulnerability management and security teams should prioritize patching and monitoring for this issue. Security teams should also review compensating controls for exposed systems and track exceptions, retest remediated assets, and close the item only after evidence is documented.

Technical summary

The HT Contact Form WordPress plugin before 2.9.3 lacks authorization checks on endpoints returning saved form drafts. Unauthenticated users can access personal data (name, email, phone, address) stored in form drafts. This issue allows unauthorized users to read sensitive information stored in form drafts, potentially leading to privacy breaches. The vulnerability can be mitigated by updating to plugin version 2.9.3 or later and monitoring for unauthorized access attempts.

Defensive priority

Unauthenticated users can access personal data stored in form drafts. Verify and restrict access to form endpoints.

Recommended defensive actions

  • Verify and restrict access to form endpoints
  • Update to plugin version 2.9.3 or later
  • Monitor for unauthorized access attempts
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions, retest remediated assets
  • Confirm whether affected product deployments exist in managed environments

Evidence notes

The HT Contact Form WordPress plugin before 2.9.3 does not perform authorization checks on saved form draft endpoints. Limited information available. To verify, defenders should check plugin versions, review form draft access controls, and monitor for unauthorized access attempts. The vulnerability allows unauthenticated users to access personal data stored in form drafts, potentially leading to privacy breaches. Defenders should verify the plugin version, review form draft access controls, and monitor for unauthorized access attempts to protect their environments.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-14206 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-14206

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-14206 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14206

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.