Authorization Bypass and Stored XSS Vulnerability in YS LeadGen Plugin by WordPress
CVE-2026-1256
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 September 2026
What is CVE-2026-1256?
The YS LeadGen plugin for WordPress is susceptible to authorization bypass and Stored Cross-Site Scripting vulnerabilities through multiple AJAX endpoints. These weaknesses are present in all versions up to and including 2.1.4 due to the absence of crucial capability checks in popup management actions. This vulnerability allows authenticated attackers with Subscriber-level access and higher to craft arbitrary popups and insert malicious JavaScript code, which subsequently executes when the affected popup is viewed, ultimately leading to the Stored XSS attack.
Affected Version(s)
YS LeadGen β Popup Builder, Popup Maker & Form Builder for WordPress | Lead Generation, Email Marketing, Sales, Con, Opt-Ins & Subscribers 0 <= 2.1.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved