Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks, CVE-2026-14206
- CVE, Research URL
- Home page URL
-
Security reports for Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks
- Published on
- Aug 10, 2026
- Research Description
- The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.
- Affected versions
-
max 2.9.3.
- Status
-
vulnerable