Sensitive Information Exposure in YS LeadGen Plugin for WordPress
CVE-2026-1255

7.5HIGH

What is CVE-2026-1255?

The YS LeadGen plugin for WordPress has a vulnerability that enables unauthenticated users to access sensitive form submission data through the 'ysleadgen_get_captured_data' AJAX action. This security flaw permits attackers to retrieve personally identifiable information (PII), including names, email addresses, and messages submitted via YS LeadGen forms. It is crucial for users of this plugin to update to a secure version to protect sensitive user data from potential exploitation.

Affected Version(s)

YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress | Lead Generation, Email Marketing, Sales, Con, Opt-Ins & Subscribers 0 <= 2.1.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Athiwat Tiprasaharn (Jitlada)
.