GHSA-25jm-cqq3-vxrfHighCVSS 7.5

The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on...

Published
August 10, 2026
Last Modified
August 10, 2026

🔗 CVE IDs covered (1)

📋 Description

The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.

🔗 References (3)