Unauthenticated Sensitive Data Exposure in SiteLeads Contact Widget by Patchstack
CVE-2026-78268
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 August 2026
What is CVE-2026-78268?
The SiteLeads lead generation contact widget and AI chatbot for WordPress is vulnerable to an unauthenticated sensitive data exposure. This vulnerability allows attackers to access sensitive information without authentication, compromising the privacy of users' data. The affected versions include SiteLeads up to 1.2.0. Website owners using this plugin should take immediate action to mitigate the risk by updating their installations.
Affected Version(s)
Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email β SiteLeads <= 1.2.0