Extension WordPress
Vulnérabilités HT Contact Form – Drag & Drop Form Builder for WordPress
Cette page rassemble les failles publiées pour HT Contact Form – Drag & Drop Form Builder for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de HT Contact Form – Drag & Drop Form Builder for WordPress
8 fiches
HT Contact Form <= 2.8.2 – Unauthenticated Stored Cross-Site Scripting via File Upload Field
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'file_upload' parameter in all versions up to, and including, 2.8.2 due to insufficient input sanitization…
*-2.8.2
2.8.3
27/05/2026
HT Contact Form – Drag & Drop Form Builder for WordPress <= 2.8.2 – Unauthenticated Stored Cross-Site Scripting
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes…
*-2.8.2
2.8.3
20/05/2026
HT Contact Form 7 <= 2.0.0 – Authenticated (Administrator+) Local File Inclusion
The HT Contact Form 7 plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary…
*-2.0.0
2.1.0
16/07/2025
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 – Unauthenticated Arbitrary File Upload
The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the temp_file_upload() function in all versions up…
*-2.2.1
2.2.2
14/07/2025
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 – Directory Traversal to Arbitrary File Move
The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation in the handle_files_upload() function in all versions up…
*-2.2.1
2.2.2
14/07/2025
HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 – Unauthenticated Arbitrary File Deletion
The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the temp_file_delete() function in all versions up…
*-2.2.1
2.2.2
14/07/2025
HT Conctact Form 7 <= 1.2.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The HT Conctact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-1.2.1
1.2.2
24/01/2025
Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks <= 1.1.5 – Cross-Site Request Forgery to Arbitrary Plugin Activation
The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.5. This is due to missing or incorrect nonce validation on…
*-1.1.5
1.1.6
28/02/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.