rootpwn

high · CVSS v3 7.5 · EPSS 0.00295

CVE-2026-1255

The YS LeadGen plugin for WordPress allows unauthenticated users to retrieve sensitive form data via the ysleadgen_get_captured_data AJAX ac

Overview

The YS LeadGen plugin for WordPress allows unauthenticated users to retrieve sensitive form data via the ysleadgen_get_captured_data AJAX action. This flaw exposes PII such as names, emails, and messages. It affects all versions up to 2.1.4.

Description

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it possible for unauthenticated attackers to retrieve all captured form submission data, including personally identifiable information (PII) such as names, email addresses, and message content submitted through YS LeadGen forms.

Impact

Confidentiality: PII exposed. Integrity: data not tampered but exposed. Availability: no direct impact. Defenders: site owners, administrators, and users whose data is collected via YS LeadGen forms.

Remediation

Update YS LeadGen to version 2.1.5 or later. If update not possible, disable the ysleadgen_get_captured_data AJAX endpoint or restrict it to authenticated users. Monitor logs for unauthorized access.

Risk context

High severity CVE with low EPSS (0.00295) indicates a moderate likelihood of exploitation but significant impact if exploited.

Affected products

  • WordPress YS LeadGen plugin

Scores

Severity
high
CVSS v2
7.8
CVSS v3
7.5
CVSS v4
EPSS
0.00295

wordpress plugin sensitive-information-exposure PII unauthenticated ajax data-exposure

← All CVEs