Description
Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.
Published: 2026-08-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an unauthenticated attacker to access sensitive user geolocation data that the plugin collects. The flaw exists because the plugin exposes the geolocation information without requiring any form of authentication or authorization. An attacker could retrieve the latitude and longitude of users who interact with the Contact Form 7 form, compromising user privacy and potentially enabling targeted attacks. The weakness maps to CWE-201, Sensitive Data Exposure.

Affected Systems

WordPress installations running the Track Geolocation Of Users Using Contact Form 7 plugin version 3.0.2 or earlier are affected. The plugin is marketed by ZealousWeb. Only the specified plugin version is impacted; no other plugins or WordPress core components are mentioned.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. The EPSS score is 0.00245 (approximately 0.25%), indicating a low but non‑zero exploitation probability; the likelihood of exploitation is therefore quantifiable. The vulnerability is not listed in CISA’s KEV catalog. Because the issue is unauthenticated, an attacker only needs to observe the form output or request the tracking endpoint; no privileged credentials are required, making exploitation straightforward if the plugin is present.

Generated by OpenCVE AI on August 20, 2026 at 17:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the plugin to the latest version available from the vendor, which removes the geolocation exposure.
  • If an update cannot be applied immediately, disable the geolocation tracking feature in the plugin’s settings or remove the plugin if the functionality is unnecessary.
  • Restrict administrative access to the plugin’s configuration pages to authorized personnel only, minimizing the chance that a misconfigured plugin exposes data.
  • Audit the site’s form handling to ensure that geolocation data is properly protected or removed before being displayed or stored.

Generated by OpenCVE AI on August 20, 2026 at 17:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Zealousweb
Zealousweb track Geolocation Of Users Using Contact Form 7
Vendors & Products Wordpress
Wordpress wordpress
Zealousweb
Zealousweb track Geolocation Of Users Using Contact Form 7
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.
Title WordPress Track Geolocation Of Users Using Contact Form 7 plugin <= 3.0.2 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Wordpress Wordpress
Zealousweb Track Geolocation Of Users Using Contact Form 7
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-19T14:39:15.284Z

Reserved: 2026-08-12T14:10:08.047Z

Link: CVE-2026-73386

cve-icon Vulnrichment

Updated: 2026-08-19T13:51:58.214Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T13:18:07.910

Modified: 2026-08-20T12:49:04.990

Link: CVE-2026-73386

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T18:00:04Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data