← WordPress Vulnerabilities
WordPress security by component

HT Contact Form – Drag & Drop Form Builder for WordPress

HT Contact Form – Drag & Drop Form Builder for WordPress is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published May 28, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: ht-contactform

CVE-2026-7052: HT Contact Form – Drag & Drop Form Builder for WordPress: Cross-site scripting

HT Contact Form – Drag & Drop Form Builder for WordPress is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.8.2.

PublishedMay 28, 2026
Known safe version> 2.8.2
Safe version
May 28, 2026 CVE-2026-7052
HT Contact Form – Drag & Drop Form Builder for WordPress: Cross-site scripting
HT Contact Form – Drag & Drop Form Builder for WordPress is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.8.2.
> 2.8.2
CVE7.2
NVDPending
May 27, 2026 CVE-2026-42728
HT Contact Form 7: Cross-site scripting
HT Contact Form 7 is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.8.2.
2.8.3
CVE7.1
NVDPending
Jul 16, 2025 CVE-2025-54015
HT Contact Form 7: Filesystem traversal
HT Contact Form 7 is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE6.6
NVDPending
Jul 15, 2025 CVE-2025-7360
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder: Code execution
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.1
NVD9.8
Jul 15, 2025 CVE-2025-7341
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder: Code execution
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.1
NVD9.8
Jul 15, 2025 CVE-2025-7340
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder: Dangerous file upload
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE9.8
NVDPending
Jan 24, 2025 CVE-2025-24726
HT Contact Form 7: Cross-site scripting
HT Contact Form 7 is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending