What is CVE-2026-73384?
CVE-2026-73384 is an unauthenticated sensitive data exposure vulnerability in the Pay with Contact Form 7 plugin versions 1.0.4 and below. It could allow remote attackers to read confidential payment or user information without any login credentials. Immediate update to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-73384, "Pay with Contact Form 7" plagininin 1.0.4 və daha əvvəlki versiyalarında autentifikasiya olunmadan həssas məlumatların ifşasına səbəb olan boşluqdur. Bu, uzaqdan heç bir giriş tələb etmədən məxfi ödəniş və ya istifadəçi məlumatlarının oxunmasına imkan verə bilər. Plaginini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which plugin is affected by CVE-2026-73384 and what versions are vulnerable?
This vulnerability was discovered in the "Pay with Contact Form 7" plugin. Versions 1.0.4 and below are affected.
What does CVE-2026-73384 allow a remote attacker to do?
This vulnerability could allow remote attackers to read confidential payment or user information without authentication, meaning no login credentials are required.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.