Impact
This vulnerability allows an unauthenticated attacker to access sensitive user geolocation data that the plugin collects. The flaw exists because the plugin exposes the geolocation information without requiring any form of authentication or authorization. An attacker could retrieve the latitude and longitude of users who interact with the Contact Form 7 form, compromising user privacy and potentially enabling targeted attacks. The weakness maps to CWE-201, Sensitive Data Exposure.
Affected Systems
WordPress installations running the Track Geolocation Of Users Using Contact Form 7 plugin version 3.0.2 or earlier are affected. The plugin is marketed by ZealousWeb. Only the specified plugin version is impacted; no other plugins or WordPress core components are mentioned.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score is 0.00245 (approximately 0.25%), indicating a low but non‑zero exploitation probability; the likelihood of exploitation is therefore quantifiable. The vulnerability is not listed in CISA’s KEV catalog. Because the issue is unauthenticated, an attacker only needs to observe the form output or request the tracking endpoint; no privileged credentials are required, making exploitation straightforward if the plugin is present.
OpenCVE Enrichment