Track Geolocation Of Users Using Contact Form 7
Track Geolocation Of Users Using Contact Form 7 has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 4.8, and the most serious one scores 5.3 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor.
1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.
2 independent researchers contributed these findings, one record each. Track Geolocation Of Users Using Contact Form 7 is installed on roughly 900 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2026-73386Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 - Unauthenticated Information Exposure
Read the full analysisVulnerability Records

Track Geolocation Of Users Using Contact Form 7
Author
ZealousWeb
Track Geolocation Of Users Using Contact Form 7 allows you to get geolocation information with their form submission. This will help you know better from where the visitor has submitted the form. Features of Track Geolocation Of Users Using Contact Form 7 Advanced Filtering & Search – Quickly locate form submissions with filters for Country, City, and Submission Date. Custom Webhook Integrations – Automate workflows by sending geolocation data to external platforms. Multi-Language Compatibility – The plugin automatically translates data. Get Geolocation details including city,state,country,zipcode,latitude/longitude. Send all this information including a static google map image in the mail with a simple shortcode. Form Specific Visual chart to get to know from where the Visitors become more. We have used 2 Types of API here one is with access token key named ipstack and another is without access token which is free named ipapi & KeyCDN. So if you do not enter access token key in plugin setting then it will fetch data with the help of free API keys. To add latitude/longitude, country, state, city in mail – [geolocation] To add latitude/longitude, country, state, city & Google map static image in the mail – [geolocation lat-long country state city gmap] To add only latitude/longitude in mail – [geolocation lat-long] To add only the country in the mail- [geolocation country] To add only the state in the mail – [geolocation state] To add only the city in the mail – [geolocation city] To add only Google map static image in the mail- [geolocation gmap] Demo for Track Geolocation Of Users Using Contact Form 7 Note: To add Google map static image in the mail you have to enable this 2 option 1. You have to enable Use HTML content-type in the Mail setting of Contact form 7. 2. You have to enable Maps Static API in Google Map API. OUR OTHER PLUGINS Abandoned Contact Form 7 Pro Accept 2 Checkout Payments Using Contact Form 7 Pro Accept Authorize.NET Payments Using Contact Form 7 Pro Accept Elavon Payments Using Contact Form 7 Pro Accept PayPal Payments Using Contact Form 7 Pro Accept Sagepay(Opayo) Payments Using Contact Form 7 Pro Accept Stripe Payments Using Contact Form 7 Pro Custom Product Options WooCommerce Pro Generate PDF Using Contact Form 7 Pro Smart Appointment & Booking Pro Smart Showcase for Google Reviews Pro User Registration Using Contact Form 7 Pro
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C