CallRail Phone Call Tracking
CallRail Phone Call Tracking has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2023; all 2 are fixed as of September 2026. Their average CVSS score is 6.3, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for CallRail Phone Call Tracking has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. CallRail Phone Call Tracking is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2023-5051CallRail Phone Call Tracking <= 0.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Read the full analysisVulnerability Records
CallRail Phone Call Tracking
Author
CallRail
CallRail is here to bring complete visibility to the marketers who rely on quality inbound leads to measure success. Our customers live in a results-driven world, and giving them a clear view into their digital marketing efforts is a first priority for CallRail. We see the opportunities in surfacing and connecting data from calls, forms, chat and beyond — helping our customers get to better outcomes. Our WordPress plugin allows you to learn detailed information about the source and web session of every caller from your website using a process called Dynamic Number Insertion. It also powers our form tracking tool, which gives you the power to attribute form submissions back to their source and learn about what the user did on your site before submitting the form. Learn more about CallRail. Check out our WP plugin support documentation.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C