Sensitive Data Exposure in Track Geolocation Plugin by WordPress
CVE-2026-73386

7.5HIGH

What is CVE-2026-73386?

The Track Geolocation Of Users Using Contact Form 7 plugin, up to version 3.0.2, has a vulnerability that allows unauthenticated users to access sensitive data. This exposure can lead to potential abuse of sensitive user information gathered through the contact forms, putting user privacy at risk and potentially enabling malicious activities. Website administrators using this plugin are urged to update to the latest secure version to mitigate any risk associated with this vulnerability.

Affected Version(s)

Track Geolocation Of Users Using Contact Form 7 <= 3.0.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan | Patchstack Bug Bounty Program
.