What is CVE-2026-14206?
CVE-2026-14206 is a missing authorization check in the HT Contact Form WordPress plugin before version 2.9.3. It allows unauthenticated users to access an endpoint and read personal data (name, email, phone, address) stored in form drafts. Immediate update to the patched version is required.
Azərbaycanca: CVE-2026-14206, HT Contact Form WordPress plaginində 2.9.3 versiyasından əvvəl avtorizasiya yoxlanışının olmamasıdır. Bu boşluq autentifikasiya olunmamış şəxslərə saxlanmış forma qaralamalarındakı ad, e-poçt, telefon, ünvan kimi şəxsi məlumatları oxumağa imkan verir. Plagin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Is authentication required to exploit CVE-2026-14206?
No, this vulnerability allows unauthenticated users to read personal data stored in form drafts.
Which plugin is affected by CVE-2026-14206 and in what version is it fixed?
CVE-2026-14206 affects the HT Contact Form WordPress plugin. The vulnerability exists before version 2.9.3, where the missing authorization check is patched.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.