CVE-2026-14206
7.5WordPress · HT Contact Form
The HT Contact Form WordPress plugin contains an information exposure vulnerability that may allow unauthenticated attackers to view sensitive data.
Executive summary
An unauthenticated information exposure vulnerability in the HT Contact Form WordPress plugin presents a significant risk of unauthorized data access.
Vulnerability
This is an information exposure vulnerability (CWE-200) that does not require authentication. An attacker can leverage this flaw to retrieve sensitive information from the application through standard web requests.
Business impact
Exposure of sensitive information can lead to unauthorized access to user records or system configuration details, potentially impacting the confidentiality of the platform. The CVSS score of 7.5 indicates a high-severity risk, particularly for businesses that rely on the plugin to manage potentially sensitive contact submissions.
Remediation
Immediate Action: Update the HT Contact Form plugin to version 2.9.3 or later.
Proactive Monitoring: Review server logs for anomalous query parameters or unexpected access to plugin directories that may indicate reconnaissance or exploitation attempts.
Compensating Controls: Use a Web Application Firewall to filter requests and block potential access to sensitive paths or files associated with the HT Contact Form plugin.
Exploitation status
Public Exploit Available: false
Analyst recommendation
The presence of a proof-of-concept makes this a credible threat despite the lack of confirmed active exploitation. Administrators should apply the vendor-provided update as a priority to secure their WordPress environment and prevent unauthorized data exposure.