Authorization Bypass and Stored XSS Vulnerability in YS LeadGen Plugin by WordPress
CVE-2026-1256

6.4MEDIUM

What is CVE-2026-1256?

The YS LeadGen plugin for WordPress is susceptible to authorization bypass and Stored Cross-Site Scripting vulnerabilities through multiple AJAX endpoints. These weaknesses are present in all versions up to and including 2.1.4 due to the absence of crucial capability checks in popup management actions. This vulnerability allows authenticated attackers with Subscriber-level access and higher to craft arbitrary popups and insert malicious JavaScript code, which subsequently executes when the affected popup is viewed, ultimately leading to the Stored XSS attack.

Affected Version(s)

YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress | Lead Generation, Email Marketing, Sales, Con, Opt-Ins & Subscribers 0 <= 2.1.4

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Athiwat Tiprasaharn (Jitlada)
Itthidej Aramsri (Boeing777)
Powpy
Waris Damkham
.