CyberRota Analysis
AI-GeneratedThe HT Contact Form plugin for WordPress versions prior to 2.9.3 is vulnerable due to a lack of authorization checks on the endpoint that retrieves saved form drafts. This flaw allows unauthenticated users to access sensitive personal data, including names, emails, phone numbers, and addresses. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data exposure risks.
Original NVD Description
The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.