Stored Cross-Site Scripting in HT Contact Form for WordPress
CVE-2026-96326
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 September 2026
What is CVE-2026-96326?
The HT Contact Form β Drag & Drop Form Builder for WordPress is subject to a Stored Cross-Site Scripting vulnerability. This issue arises from inadequate input sanitization and output escaping within the Rich Text Editor Field. As a result, unauthenticated attackers can inject malicious scripts, which execute whenever a user visits an affected page. This highlights the critical need for developers to enhance their security practices to prevent such vulnerabilities in web applications.
Affected Version(s)
HT Contact Form β Drag & Drop Form Builder for WordPress 0 <= 2.10.2