PatchSiren

HT CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review HT CVE published 2026-08-10

CVE-2026-14206

The HT Contact Form WordPress plugin before 2.9.3 has a vulnerability that allows unauthenticated users to access personal data stored in form drafts. This issue arises from the plugin's lack of authorization checks on endpoints returning saved form drafts. The vulnerability can lead to privacy breaches, as sensitive information such as names, emails, phone numbers, and addresses stored in form drafts can [truncated]