WordPress security by component
HT Contact Form – Drag & Drop Form Builder for WordPress
Plugin description
HT Contact Form – Drag & Drop Form Builder for WordPress is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published May 28, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
ht-contactformLatest vulnerability
CVE-2026-7052: HT Contact Form – Drag & Drop Form Builder for WordPress: Cross-site scripting
HT Contact Form – Drag & Drop Form Builder for WordPress is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.8.2.
| Safe version |
|
||
|---|---|---|---|
| May 28, 2026 |
CVE-2026-7052
HT Contact Form – Drag & Drop Form Builder for WordPress: Cross-site scripting
HT Contact Form – Drag & Drop Form Builder for WordPress is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.8.2.
|
> 2.8.2 |
CVE7.2
NVDPending
|
| May 27, 2026 |
CVE-2026-42728
HT Contact Form 7: Cross-site scripting
HT Contact Form 7 is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.8.2.
|
2.8.3 |
CVE7.1
NVDPending
|
| Jul 16, 2025 |
CVE-2025-54015
HT Contact Form 7: Filesystem traversal
HT Contact Form 7 is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE6.6
NVDPending
|
| Jul 15, 2025 |
CVE-2025-7360
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder: Code execution
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.1
NVD9.8
|
| Jul 15, 2025 |
CVE-2025-7341
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder: Code execution
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.1
NVD9.8
|
| Jul 15, 2025 |
CVE-2025-7340
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder: Dangerous file upload
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Jan 24, 2025 |
CVE-2025-24726
HT Contact Form 7: Cross-site scripting
HT Contact Form 7 is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|