Impact
HT Contact Form is a WordPress plugin that, before version 2.9.3, lacks an authorization check on the endpoint that retrieves a saved form draft, allowing any unauthenticated user to fetch personal data such as name, email, phone, and address. This missing authentication results in a direct disclosure of sensitive information and represents a classic broken access control flaw. The documentation does not mention an available patch for versions below 2.9.3, and it is unknown whether an official fix exists for those installations.
Affected Systems
Installation of the HT Contact Form WordPress plugin on any version older than 2.9.3 is vulnerable. Site administrators running this plugin should verify their current version and plan an upgrade if applicable.
Risk and Exploitability
An attacker can exploit the flaw by sending an unauthenticated HTTP request to the exposed draft retrieval endpoint, retrieving the contents of any stored draft without credentials. Because no authentication is required, the attack vector is straightforward and can be executed from any network. The EPSS score is not provided, and the vulnerability is not listed in CISA's KEV catalog, indicating no confirmed exploitation yet, yet the potential for mass disclosure of personal information presents a significant risk that warrants prompt action.
OpenCVE Enrichment