AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-14206

HIGH · CVSS 7.5 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The HT Contact Form plugin for WordPress versions prior to 2.9.3 is vulnerable due to a lack of authorization checks on the endpoint that retrieves saved form drafts. This flaw allows unauthenticated users to access sensitive personal data, including names, emails, phone numbers, and addresses. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data exposure risks.

CVE
CVE-2026-14206
Severity
HIGH
CVSS
7.5
EPSS
0.32%
WordPress

Original NVD Description

The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.