Impact
HT Contact Form is a WordPress plugin that, before version 2.9.3, lacks an authorization check on the endpoint that retrieves a saved form draft, allowing any unauthenticated user to fetch personal data such as name, email, phone, and address. This missing authentication results in a direct disclosure of sensitive information.
Affected Systems
Installation of the HT Contact Form WordPress plugin on any version older than 2.9.3 is vulnerable. Site administrators running this plugin should verify their current version and plan an upgrade if applicable.
Risk and Exploitability
An attacker can exploit the flaw by sending an unauthenticated HTTP request to the exposed draft retrieval endpoint, retrieving the contents of any stored draft without credentials. Because no authentication is required, the attack vector is straightforward and can be executed from any network. The CVSS score of 7.5 reflects a moderate‑to‑high severity, and the EPSS score of <1% suggests a low yet non‑zero likelihood of exploitation; the vulnerability is not listed in CISA's KEV catalog, indicating no confirmed exploitation yet. However, the potential for mass disclosure of personal information presents a significant risk that warrants prompt action.
OpenCVE Enrichment