CVE-2026-73384: WordPress Pay with Contact Form 7 plugin <= 1.0.4 - Sensitive Data Exposure vulnerability
Published Aug 19, 2026
·Updated
Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
Affected Software
1 affected component
WordPress plugin/Pay with Contact Form 7<=1.0.4
Event History
Aug 19, 2026
CVE Published
via MITRE·12:38 PM
Data Sourced
via MITRE·12:38 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated and remotely exploitable. An attacker does not need WordPress credentials or user interaction to attempt exploitation.
2
What is the potential impact?
Successful exploitation can expose sensitive data. The supplied severity vector indicates high confidentiality impact, with no stated integrity or availability impact.
3
Which installations are affected?
Pay with Contact Form 7 versions 1.0.4 and earlier are affected. The provided information does not identify any configuration prerequisite or mitigation other than using an unaffected version.