What the vulnerability does
01Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in HT Plugins HT Contact Form 7 ht-contactform allows PHP Local File Inclusion.This issue affects HT Contact Form 7: from n/a through <= 2.0.0.
Explanation of Vulnerability in Simple Terms
02Summary
HT Contact Form 7 versions 2.0.0 and earlier contain a vulnerability that allows high-privilege users to read sensitive data, modify site content, or disrupt service. The vulnerability requires network access and high administrative privileges to exploit. Site administrators should update to a version newer than 2.0.0 as soon as a patch becomes available.
What an attacker can do
03Attacker Capabilities
Read sensitive data, modify site content, or disrupt service availability.
Potential impact on your site
04Site Impact
High-privilege user accounts could be compromised to access data, alter forms, or cause downtime.
Conditions required to exploit
05Prerequisites
Attacker must have high-level administrative privileges on the site.
Key dates
06Disclosure timeline
July 16, 2025
CVE published
April 28, 2026
Record updated