Sceawere
Vulnerability Detail
CVE-2026-73386UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Sensitive Data Exposure
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 4h ago
- Vendor
- ZealousWeb
- Product
- Track Geolocation Of Users Using Contact Form 7
- Attack Type
- CWE-201 Insertion of Sensitive Information Into Sent Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-08-19T13:18:07.910Z",
"pubdate": "2026-08-19T13:18:07.910Z",
"executiveSummary": "An unauthenticated sensitive data exposure vulnerability has been identified in the Track Geolocation Of Users Using Contact Form 7 plugin, specifically affecting versions 3.0.2 and prior.\nThis security flaw allows remote, unauthenticated attackers to access and exfiltrate sensitive user geolocation and tracking data collected by the application without requiring any prior authentication or special privileges.\nThe affected product is the Track Geolocation Of Users Using Contact Form 7 WordPress plugin.\nThe risk implications are severe, as unauthorized data harvesting can lead to privacy violations, surveillance of users, and potential exposure of Personally Identifiable Information (PII).\nAn attacker requires network access to the target WordPress installation to exploit this vulnerability, leveraging the lack of access controls on the vulnerable endpoint.\nNo complex exploitation requirements or user interactions are necessary to compromise the exposed data, heightening the overall risk profile of the affected installations.",
"technicalDetails": "The root cause of the vulnerability lies in the inadequate implementation of access control mechanisms and session validation within the Track Geolocation Of Users Using Contact Form 7 plugin for versions 3.0.2 and below.\nThe vulnerable component fails to restrict access to sensitive tracking endpoints or administrative data retrieval functions, permitting arbitrary HTTP requests to fetch stored geolocation records without verifying the requester's authentication status or authorization level.\nThe attack flow begins with an unauthenticated remote adversary identifying the exposed endpoint or functional handler responsible for serving user geolocation data.\nUpon locating the endpoint, the attacker constructs and transmits a crafted HTTP request directly to the server hosting the vulnerable WordPress plugin.\nBecause the application lacks proper input validation and access checks on this specific functionality, it processes the request and returns the sensitive tracking datasets directly in the HTTP response body.\nNetwork exposure is fully public-facing, as the vulnerable functions are accessible over standard HTTP/HTTPS protocols via the web interface of the WordPress site.\nPrivilege requirements are nonexistent, allowing any external entity with network connectivity to execute the data retrieval routine successfully.\nThe payload behavior involves querying the underlying database tables or data storage mechanisms utilized by the plugin to aggregate user location metrics and serializing the output for unauthorized consumption.\nThe post-exploitation impact includes the systematic harvesting of user telemetry, potential mapping of user locations, compliance violations regarding data privacy regulations, and the aggregation of intelligence that could facilitate further targeted attacks against the user base."
}