plugin

Ht Contactform Vulnerabilities

9 known security issues reported for the Ht Contactform WordPress plugin. Most recent disclosed Aug 6, 2026.

3 critical 2 high 4 medium

Running Ht Contactform on your site? Check whether your installed version is affected.

Scan your site free

HT Contact Form <= 2.9.2 - Unauthenticated Information Exposure

medium

The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.2. This makes it possible for unauthenticated attackers to extract saved form draft data.

CVSS:
5.3
Affected:
up to 2.9.2
Fixed in:
2.9.3
Disclosed:
Aug 6, 2026

CVE-2026-14206 on NVD →

HT Contact Form <= 2.8.2 - Unauthenticated Stored Cross-Site Scripting via File Upload Field

high

The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'file_upload' parameter in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i...

CVSS:
7.2
Affected:
up to 2.8.2
Fixed in:
2.8.3
Disclosed:
May 27, 2026

CVE-2026-7052 on NVD →

HT Contact Form – Drag & Drop Form Builder for WordPress <= 2.8.2 - Unauthenticated Stored Cross-Site Scripting

high

The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
7.2
Affected:
up to 2.8.2
Fixed in:
2.8.3
Disclosed:
May 20, 2026

CVE-2026-42728 on NVD →

HT Contact Form 7 <= 2.0.0 - Authenticated (Administrator+) Local File Inclusion

medium

The HT Contact Form 7 plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those f...

CVSS:
6.6
Affected:
up to 2.0.0
Fixed in:
2.1.0
Disclosed:
Jul 16, 2025

CVE-2025-54015 on NVD →

HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload

critical

The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the temp_file_upload() function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to...

CVSS:
9.8
Affected:
up to 2.2.1
Fixed in:
2.2.2
Disclosed:
Jul 14, 2025

CVE-2025-7340 on NVD →

HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Directory Traversal to Arbitrary File Move

critical

The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation in the handle_files_upload() function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attac...

CVSS:
9.1
Affected:
up to 2.2.1
Fixed in:
2.2.2
Disclosed:
Jul 14, 2025

CVE-2025-7360 on NVD →

HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Deletion

critical

The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the temp_file_delete() function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attack...

CVSS:
9.1
Affected:
up to 2.2.1
Fixed in:
2.2.2
Disclosed:
Jul 14, 2025

CVE-2025-7341 on NVD →

HT Conctact Form 7 <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The HT Conctact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pag...

CVSS:
6.4
Affected:
up to 1.2.1
Fixed in:
1.2.2
Disclosed:
Jan 24, 2025

CVE-2025-24726 on NVD →

Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks <= 1.1.5 - Cross-Site Request Forgery to Arbitrary Plugin Activation

medium

The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.5. This is due to missing or incorrect nonce validation on the 'plugin_activation' function. This makes it possible for unauthenticated attackers...

CVSS:
4.3
Affected:
up to 1.1.5
Fixed in:
1.1.6
Disclosed:
Feb 28, 2023

CVE-2023-0484 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database