Extension WordPress

Vulnérabilités HT Contact Form – Drag & Drop Form Builder for WordPress

Cette page rassemble les failles publiées pour HT Contact Form – Drag & Drop Form Builder for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.

8Vulnérabilités
3Critiques
8Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de HT Contact Form – Drag & Drop Form Builder for WordPress

8 fiches

CVE-2026-7052 Élevée · 7,2
HT Contact Form – Drag & Drop Form Builder for WordPress

HT Contact Form <= 2.8.2 – Unauthenticated Stored Cross-Site Scripting via File Upload Field

The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'file_upload' parameter in all versions up to, and including, 2.8.2 due to insufficient input sanitization…

Versions affectées

*-2.8.2

Correctif

2.8.3

Publication

27/05/2026

CVE-2026-42728 Élevée · 7,2
HT Contact Form – Drag & Drop Form Builder for WordPress

HT Contact Form – Drag & Drop Form Builder for WordPress <= 2.8.2 – Unauthenticated Stored Cross-Site Scripting

The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-2.8.2

Correctif

2.8.3

Publication

20/05/2026

CVE-2025-54015 Moyenne · 6,6
HT Contact Form – Drag & Drop Form Builder for WordPress

HT Contact Form 7 <= 2.0.0 – Authenticated (Administrator+) Local File Inclusion

The HT Contact Form 7 plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary…

Versions affectées

*-2.0.0

Correctif

2.1.0

Publication

16/07/2025

CVE-2025-7340 Critique · 9,8
HT Contact Form – Drag & Drop Form Builder for WordPress

HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 – Unauthenticated Arbitrary File Upload

The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the temp_file_upload() function in all versions up…

Versions affectées

*-2.2.1

Correctif

2.2.2

Publication

14/07/2025

CVE-2025-7360 Critique · 9,1
HT Contact Form – Drag & Drop Form Builder for WordPress

HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 – Directory Traversal to Arbitrary File Move

The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation in the handle_files_upload() function in all versions up…

Versions affectées

*-2.2.1

Correctif

2.2.2

Publication

14/07/2025

CVE-2025-7341 Critique · 9,1
HT Contact Form – Drag & Drop Form Builder for WordPress

HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 – Unauthenticated Arbitrary File Deletion

The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the temp_file_delete() function in all versions up…

Versions affectées

*-2.2.1

Correctif

2.2.2

Publication

14/07/2025

CVE-2025-24726 Moyenne · 6,4
HT Contact Form – Drag & Drop Form Builder for WordPress

HT Conctact Form 7 <= 1.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The HT Conctact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-1.2.1

Correctif

1.2.2

Publication

24/01/2025

CVE-2023-0484 Moyenne · 4,3
HT Contact Form – Drag & Drop Form Builder for WordPress

Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks <= 1.1.5 – Cross-Site Request Forgery to Arbitrary Plugin Activation

The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.5. This is due to missing or incorrect nonce validation on…

Versions affectées

*-1.1.5

Correctif

1.1.6

Publication

28/02/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités