Cross-Site Scripting Vulnerability in HT Plugins HT Contact Form 7
CVE-2026-42728

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 May 2026

What is CVE-2026-42728?

A Cross-Site Scripting (XSS) vulnerability allows attackers to inject malicious scripts into web pages viewed by users of the HT Plugins HT Contact Form 7. When exploited, this flaw can lead to the storage of the attacker's script in the application, compromising the security of user sessions and potentially leading to data theft or other malicious actions. The affected versions include those from n/a up to 2.8.2. It is crucial for users to promptly update to the latest version and implement security measures to safeguard against potential exploits.

Affected Version(s)

HT Contact Form 7 0 <= 2.8.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo | Patchstack Bug Bounty Program
.