Stored DOM-Based Cross-Site Scripting in HT Contact Form Plugin for WordPress
CVE-2026-93303

7.2HIGH

What is CVE-2026-93303?

The HT Contact Form – Drag & Drop Form Builder for WordPress plugin exposes a serious security vulnerability that allows unauthenticated attackers to perform Stored DOM-Based Cross-Site Scripting. This is achieved through an insufficiently sanitized 'form_data' Rich Text Field when utilizing the Draft Save/Resume feature. Attackers can craft malicious draft resume URLs exploiting the draft_key and access_token, which can lead to arbitrary web scripts being injected and executed whenever an unsuspecting user accesses an affected page. It's critical for users of the plugin to implement the latest updates to mitigate potential exploits.

Affected Version(s)

HT Contact Form – Drag & Drop Form Builder for WordPress 0 <= 2.10.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kuzomo
.