CVE-2026-73386: WordPress Track Geolocation Of Users Using Contact Form 7 plugin <= 3.0.2 - Sensitive Data Exposure vulnerability
Published Aug 19, 2026
·Updated
Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.
Affected Software
1 affected component
Contact Form 7<=3.0.2
Event History
Aug 19, 2026
CVE Published
via MITRE·12:38 PM
Data Sourced
via MITRE·12:38 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or other privileges. The attack vector is network-accessible and requires no user interaction.
2
What is the impact if exploitation succeeds?
The vulnerability can expose sensitive data. The provided severity vector indicates high confidentiality impact, with no stated integrity or availability impact.
3
Which plugin versions are affected?
Track Geolocation Of Users Using Contact Form 7 versions 3.0.2 and earlier are affected.