Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-14206

Опубликовано: 10 авг. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.

EPSS

Процентиль: 24%
0.00316
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
github
около 1 месяца назад

The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.

EPSS

Процентиль: 24%
0.00316
Низкий

7.5 High

CVSS3

Дефекты

CWE-200