Description
Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Stored XSS.This issue affects WP2LEADS: from n/a through <= 3.5.0.
Published: 2025-05-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a Cross‑Site Request Forgery (CSRF) flaw that permits an attacker to inject arbitrary content into the WordPress WP2LEADS plugin. Once the attacker has gained the victim’s authenticated session or lures the victim to visit a crafted link, the malicious input is accepted and stored by the plugin. When end users view the affected content, the injected data is rendered as executable code, leading to a stored Cross‑Site Scripting (XSS) attack. The flaw violates the defect “Improper Neutralization of Stored Cross‑Site Scripting” (CWE‑352) and undermines the confidentiality, integrity, and availability of the hosted website.

Affected Systems

WordPress installations using the WP2LEADS plugin version 3.5.0 or earlier are affected. The back‑end component referred to as ‘Saleswonder Team: Tobias WP2LEADS’ is specifically vulnerable; no other plugin or system components are listed as impacted.

Risk and Exploitability

The assigned CVSS score of 7.1 categorizes the risk as high; however, the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not present in the CISA KEV catalog, suggesting it has not yet been widely leveraged by adversaries. The attack vector is via a crafted request that an authenticated user will unknowingly submit, meaning that an attacker only requires the ability to entice a legitimate user to click a link or submit a form. No network‑level exploitation or privilege escalation is required, reducing the overall effort for an attacker but still allowing significant damage if exploited.

Generated by OpenCVE AI on April 30, 2026 at 20:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP2LEADS to the most recent release that addresses the CSRF and XSS flaw.
  • If an upgrade is not immediately possible, disable the affected plugin or restrict its use to trusted administrators only, limiting the number of users who could be tricked into submitting malicious data.
  • Implement a CSRF token verification for all data‑modifying actions within the plugin and deploy a web‑application firewall rule that blocks the specific pattern of malicious payloads identified in the vulnerability report.

Generated by OpenCVE AI on April 30, 2026 at 20:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-15374 Cross-Site Request Forgery (CSRF) vulnerability in Tobias WP2LEADS allows Stored XSS.This issue affects WP2LEADS: from n/a through 3.5.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Tobias WP2LEADS allows Stored XSS.This issue affects WP2LEADS: from n/a through 3.5.0. Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Stored XSS.This issue affects WP2LEADS: from n/a through <= 3.5.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 15 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 18:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Tobias WP2LEADS allows Stored XSS.This issue affects WP2LEADS: from n/a through 3.5.0.
Title WordPress WP2LEADS plugin <= 3.5.0 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:28.897Z

Reserved: 2025-04-14T11:30:45.183Z

Link: CVE-2025-32922

cve-icon Vulnrichment

Updated: 2025-05-15T18:29:21.689Z

cve-icon NVD

Status : Deferred

Published: 2025-05-15T19:15:56.983

Modified: 2026-04-23T15:29:22.297

Link: CVE-2025-32922

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T20:15:16Z

Weaknesses