{"id":"CVE-2026-14206","title":"The HT Contact Form  WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in…","summary":"The HT Contact Form  WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in…","severity":"none","published":"2026-08-10","updated":"2026-08-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14206","references":[{"url":"https://wpscan.com/vulnerability/36ae857c-6812-46e0-a0e7-6c868108ef39/","label":"contact@wpscan.com"}],"tags":["nvd"],"ingestedAt":"2026-08-10T07:39:17.172Z","epss":0.00434,"epssPercentile":0.34986,"slug":"CVE-2026-14206","body":"## Overview\n\nThe HT Contact Form  WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}