{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ht-contact-form--drag--drop-form-builder-for-wordpress--2.10.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:ht_contact_form_drag_drop_form_builder_for_wordpress:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-93303"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["HT Contact Form – Drag \u0026 Drop Form Builder for WordPress (\u003c= 2.10.1)"],"_cs_severities":["high"],"_cs_tags":["web-application","wordpress","xss"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe HT Contact Form - Drag \u0026amp; Drop Form Builder for WordPress plugin is vulnerable to a stored DOM-based cross-site scripting (XSS) vulnerability (CVE-2026-93303) affecting all versions up to and including 2.10.1. The flaw resides in the 'form_data' Rich Text Field, specifically within the draft save and resume functionality. Insufficient input sanitization and output escaping allow unauthenticated attackers to inject malicious scripts into saved form drafts. To exploit this, an attacker must trick an authenticated user into interacting with a crafted URL containing a valid 'draft_key' and 'access_token', which the attacker can retrieve from the plugin's response. Successful execution occurs in the context of the victim's browser session, potentially allowing unauthorized actions or session hijacking.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of an administrator or user accessing the injected form page. This could result in unauthorized administrative actions, sensitive data exfiltration, or the creation of new administrative accounts within the WordPress instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch immediately by upgrading the HT Contact Form - Drag \u0026amp; Drop Form Builder for WordPress plugin to a version greater than 2.10.1.\u003c/li\u003e\n\u003cli\u003eAudit WordPress site logs for anomalous POST requests to the plugin's draft save endpoints if unauthorized modifications are suspected.\u003c/li\u003e\n\u003cli\u003eImplement a strict Content Security Policy (CSP) to mitigate the impact of potential XSS attacks by restricting the sources of executable scripts.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-25T08:55:15Z","date_published":"2026-09-25T08:55:15Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wp-ht-contact-form-xss/","summary":"An unauthenticated stored DOM-based cross-site scripting vulnerability in the HT Contact Form plugin for WordPress allows attackers to execute arbitrary scripts via crafted draft resume URLs.","title":"Stored DOM-Based XSS in HT Contact Form WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-wp-ht-contact-form-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - HT Contact Form – Drag \u0026 Drop Form Builder for WordPress (\u003c= 2.10.1)","version":"https://jsonfeed.org/version/1.1"}