high · CVSS v3 7.5 · EPSS 0.00295
CVE-2026-1255
The YS LeadGen plugin for WordPress allows unauthenticated users to retrieve sensitive form data via the ysleadgen_get_captured_data AJAX ac
Overview
The YS LeadGen plugin for WordPress allows unauthenticated users to retrieve sensitive form data via the ysleadgen_get_captured_data AJAX action. This flaw exposes PII such as names, emails, and messages. It affects all versions up to 2.1.4.
Description
The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it possible for unauthenticated attackers to retrieve all captured form submission data, including personally identifiable information (PII) such as names, email addresses, and message content submitted through YS LeadGen forms.
Impact
Confidentiality: PII exposed. Integrity: data not tampered but exposed. Availability: no direct impact. Defenders: site owners, administrators, and users whose data is collected via YS LeadGen forms.
Remediation
Update YS LeadGen to version 2.1.5 or later. If update not possible, disable the ysleadgen_get_captured_data AJAX endpoint or restrict it to authenticated users. Monitor logs for unauthorized access.
Risk context
High severity CVE with low EPSS (0.00295) indicates a moderate likelihood of exploitation but significant impact if exploited.
Affected products
- WordPress YS LeadGen plugin
Scores
- Severity
- high
- CVSS v2
- 7.8
- CVSS v3
- 7.5
- CVSS v4
- —
- EPSS
- 0.00295