Stored DOM-Based Cross-Site Scripting in HT Contact Form Plugin for WordPress
CVE-2026-93303
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 September 2026
What is CVE-2026-93303?
The HT Contact Form β Drag & Drop Form Builder for WordPress plugin exposes a serious security vulnerability that allows unauthenticated attackers to perform Stored DOM-Based Cross-Site Scripting. This is achieved through an insufficiently sanitized 'form_data' Rich Text Field when utilizing the Draft Save/Resume feature. Attackers can craft malicious draft resume URLs exploiting the draft_key and access_token, which can lead to arbitrary web scripts being injected and executed whenever an unsuspecting user accesses an affected page. It's critical for users of the plugin to implement the latest updates to mitigate potential exploits.
Affected Version(s)
HT Contact Form β Drag & Drop Form Builder for WordPress 0 <= 2.10.1