CVE-2026-96326 Overview
CVE-2026-96326 affects the HT Contact Form – Drag & Drop Form Builder plugin for WordPress. The vulnerability enables Stored Cross-Site Scripting (XSS) through the Rich Text Editor Field. All versions up to and including 2.10.2 are affected. Unauthenticated attackers can inject arbitrary web scripts that execute when users visit affected pages. The flaw stems from insufficient input sanitization and output escaping in the plugin's rich text handling logic. This vulnerability is classified under [CWE-79] Improper Neutralization of Input During Web Page Generation.
Critical Impact
Unauthenticated attackers can inject persistent JavaScript into WordPress pages, enabling session theft, credential harvesting, and administrative account takeover when victims load affected pages.
Affected Products
- HT Contact Form – Drag & Drop Form Builder for WordPress plugin
- All versions up to and including 2.10.2
- WordPress sites using the plugin's Rich Text Editor Field
Discovery Timeline
- 2026-09-29 - CVE-2026-96326 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-96326
Vulnerability Analysis
The HT Contact Form plugin exposes a Rich Text Editor Field for form submissions. The plugin fails to sanitize input passed through this field and does not escape it on output. As a result, attacker-supplied HTML and JavaScript persist in the WordPress database. The payload executes in the browser context of any user who later loads a page rendering the stored form data. Because exploitation requires no authentication, any public form using this field becomes an injection point.
The stored nature of the flaw amplifies impact. A single submission can affect every visitor, including administrators reviewing form entries. Scope change in the vulnerability rating reflects the ability to affect components beyond the plugin itself, such as the WordPress admin session.
Root Cause
The root cause lies in the plugin's handling of Rich Text Editor Field content. Input passes through the form submission pipeline without adequate sanitization functions such as wp_kses_post() or sanitize_textarea_field(). Output rendering skips escaping helpers such as esc_html() or esc_attr(). This dual failure allows raw <script> tags and event handler attributes to survive storage and render as executable code.
Attack Vector
An unauthenticated attacker submits a crafted payload through the vulnerable Rich Text Editor Field on any public-facing form. The malicious markup persists in the WordPress database. When an administrator opens the submission in the backend, or when another visitor loads a page displaying the content, the injected JavaScript executes. Attackers commonly leverage this pattern to steal authentication cookies, create rogue administrator accounts, or redirect visitors to malware distribution sites.
The vulnerability mechanism is described in the Wordfence Vulnerability Report and remediation details are visible in the WordPress Plugin Changeset.
Detection Methods for CVE-2026-96326
Indicators of Compromise
- Unexpected <script> tags, onerror, onload, or javascript: URIs stored in form submission records
- New WordPress administrator accounts created without authorized change requests
- Outbound requests from visitor browsers to unfamiliar domains after loading form pages
- Modifications to WordPress theme files or wp_options entries following form submissions
Detection Strategies
- Audit database tables associated with HT Contact Form submissions for HTML tags and JavaScript event handlers
- Review web server logs for POST requests to form endpoints containing encoded script payloads
- Monitor Content Security Policy (CSP) violation reports for inline script execution on pages hosting the plugin
- Compare installed plugin version against 2.10.2 across all managed WordPress instances
Monitoring Recommendations
- Enable WordPress activity logging for administrator account creation and role changes
- Deploy a web application firewall rule that inspects form field payloads for common XSS signatures
- Alert on any modification to plugin files, themes, or privileged user tables following form submission events
How to Mitigate CVE-2026-96326
Immediate Actions Required
- Update the HT Contact Form plugin to a version later than 2.10.2 as soon as the vendor publishes a patched release
- Audit all existing form submissions for injected scripts and purge malicious entries from the database
- Review WordPress user accounts and remove any unauthorized administrator or editor accounts
- Force password resets and session invalidation for all privileged WordPress accounts
Patch Information
A code change addressing the vulnerability is available in the WordPress Plugin Changeset 3714946. Administrators should apply the patched plugin version via the WordPress plugin manager. Verify successful update by checking the plugin version reported in the WordPress admin dashboard.
Workarounds
- Disable the HT Contact Form plugin until the patched release is installed if forms are non-essential
- Remove or disable Rich Text Editor Fields from all forms created with the plugin
- Deploy a WAF rule blocking <script>, on*=, and javascript: patterns in submissions to form endpoints
- Restrict administrator access to form submission review pages through IP allowlisting until remediation completes
# Configuration example: WP-CLI commands to identify and disable the vulnerable plugin
wp plugin list --name=ht-contact-form --field=version
wp plugin deactivate ht-contact-form
wp plugin update ht-contact-form
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.