Impact
The YS LeadGen plugin for WordPress allows unauthenticated users to call the 'ysleadgen_get_captured_data' AJAX action. This action returns all captured form submission data, which can include names, email addresses and message content. The result is a sensitive information disclosure that exposes personal identifiable information but does not provide code execution or other direct compromises.
Affected Systems
WordPress users running any version of the YS LeadGen – Popup Builder, Popup Maker & Form Builder plugin up to and including 2.1.4. The vulnerability affects all installations of this plugin regardless of site configuration because the AJAX action is globally accessible to any visitor.
Risk and Exploitability
The vulnerability scores a 7.5 on the CVSS scale and an EPSS score of < 1%, indicating that real world exploitation is considered unlikely at present. It is not listed in the CISA KEV catalog. The only requirement to exploit the flaw is network access to a WordPress site that has the vulnerable plugin installed; no authentication is required, so the attack vector is effectively “network over AJAX”.
OpenCVE Enrichment