CVE-2026-14206: HT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data Disclosure
Published Aug 10, 2026
·Updated
The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.
Affected Software
1 affected component
WordPress HT Contact Form<2.9.3
Event History
Aug 10, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-14206?
CVE-2026-14206 has a risk rating of 54, indicating a moderate severity level.
2
How do I fix CVE-2026-14206?
To fix CVE-2026-14206, update the HT Contact Form plugin to version 2.9.3 or later.
3
What data can be disclosed due to CVE-2026-14206?
CVE-2026-14206 allows unauthenticated users to access personal data such as name, email, phone, and address from saved form drafts.
4
Is CVE-2026-14206 specific to certain versions of the plugin?
Yes, CVE-2026-14206 affects the HT Contact Form plugin versions prior to 2.9.3.
5
What type of vulnerability is CVE-2026-14206 classified as?
CVE-2026-14206 is classified as an information leak vulnerability.