CVE-2026-14206

7.5

WordPress · HT Contact Form

The HT Contact Form WordPress plugin contains an information exposure vulnerability that may allow unauthenticated attackers to view sensitive data.

Executive summary

An unauthenticated information exposure vulnerability in the HT Contact Form WordPress plugin presents a significant risk of unauthorized data access.

Vulnerability

This is an information exposure vulnerability (CWE-200) that does not require authentication. An attacker can leverage this flaw to retrieve sensitive information from the application through standard web requests.

Business impact

Exposure of sensitive information can lead to unauthorized access to user records or system configuration details, potentially impacting the confidentiality of the platform. The CVSS score of 7.5 indicates a high-severity risk, particularly for businesses that rely on the plugin to manage potentially sensitive contact submissions.

Remediation

Immediate Action: Update the HT Contact Form plugin to version 2.9.3 or later.

Proactive Monitoring: Review server logs for anomalous query parameters or unexpected access to plugin directories that may indicate reconnaissance or exploitation attempts.

Compensating Controls: Use a Web Application Firewall to filter requests and block potential access to sensitive paths or files associated with the HT Contact Form plugin.

Exploitation status

Public Exploit Available: false

Analyst recommendation

The presence of a proof-of-concept makes this a credible threat despite the lack of confirmed active exploitation. Administrators should apply the vendor-provided update as a priority to secure their WordPress environment and prevent unauthorized data exposure.

More WordPress CVEs