WordPress · Contact Form · CVE-2026-93303
**Name of the Vulnerable Software and Affected Versions**
HT Contact Form – Drag & Drop Form Builder for WordPress versions prior to 2.10.2
**Description**
Insufficient input sanitization and output escaping in the `form data` Rich Text Field allow unauthenticated attackers to perform Stored DOM-Based Cross-Site Scripting. This occurs during the Draft Save/Resume process, enabling the injection of arbitrary web scripts into pages. These scripts execute when a user accesses the affected page. To exploit this, an attacker must trick a user into clicking a specially crafted draft resume URL created using the `draft key` and `access token` variables returned in the save response.
**Recommendations**
Update to a version newer than 2.10.1.