PT-2026-69340 · WordPress · Contact Form
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HT Contact Form WordPress plugin versions prior to 2.9.3
Description
An authorization bypass exists in the endpoint that returns saved form drafts. This allows unauthenticated users to access and read personal data stored within these drafts, including names, emails, phone numbers, and addresses.
Recommendations
Update HT Contact Form WordPress plugin to version 2.9.3 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contact Form