Unauthenticated Sensitive Data Exposure in SiteLeads Contact Widget by Patchstack
CVE-2026-78268

7.5HIGH

What is CVE-2026-78268?

The SiteLeads lead generation contact widget and AI chatbot for WordPress is vulnerable to an unauthenticated sensitive data exposure. This vulnerability allows attackers to access sensitive information without authentication, compromising the privacy of users' data. The affected versions include SiteLeads up to 1.2.0. Website owners using this plugin should take immediate action to mitigate the risk by updating their installations.

Affected Version(s)

Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LevinityCyber | Patchstack Bug Bounty Program
.