CVE-2026-42728: WordPress HT Contact Form 7 plugin <= 2.8.2 - Cross Site Scripting (XSS) vulnerability
Published May 27, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Contact Form 7 ht-contactform allows Stored XSS.This issue affects HT Contact Form 7: from n/a through <= 2.8.2.
Affected Software
1 affected component
HT Plugins HT Contact Form 7<=2.8.2
Event History
May 27, 2026
CVE Published
via MITRE·09:49 AM
Data Sourced
via MITRE·09:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-42728?
CVE-2026-42728 has a high severity rating of 7.1.
2
How do I fix CVE-2026-42728?
To fix CVE-2026-42728, update the HT Contact Form 7 plugin to the latest version beyond 2.8.2.
3
What type of vulnerability is CVE-2026-42728?
CVE-2026-42728 is a Cross Site Scripting (XSS) vulnerability that allows stored XSS attacks.
4
Which versions of HT Contact Form 7 are affected by CVE-2026-42728?
CVE-2026-42728 affects HT Contact Form 7 versions from n/a to 2.8.2.
5
What are the potential impacts of CVE-2026-42728?
CVE-2026-42728 could allow attackers to execute arbitrary scripts in the user’s browser, leading to data theft or session hijacking.