Description
The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it possible for unauthenticated attackers to retrieve all captured form submission data, including personally identifiable information (PII) such as names, email addresses, and message content submitted through YS LeadGen forms.
Published: 2026-09-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The YS LeadGen plugin for WordPress allows unauthenticated users to call the 'ysleadgen_get_captured_data' AJAX action. This action returns all captured form submission data, which can include names, email addresses and message content. The result is a sensitive information disclosure that exposes personal identifiable information but does not provide code execution or other direct compromises.

Affected Systems

WordPress users running any version of the YS LeadGen – Popup Builder, Popup Maker & Form Builder plugin up to and including 2.1.4. The vulnerability affects all installations of this plugin regardless of site configuration because the AJAX action is globally accessible to any visitor.

Risk and Exploitability

The vulnerability scores a 7.5 on the CVSS scale and an EPSS score of < 1%, indicating that real world exploitation is considered unlikely at present. It is not listed in the CISA KEV catalog. The only requirement to exploit the flaw is network access to a WordPress site that has the vulnerable plugin installed; no authentication is required, so the attack vector is effectively “network over AJAX”.

Generated by OpenCVE AI on September 19, 2026 at 23:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the YS LeadGen plugin to the latest available version, which removes the unauthenticated AJAX endpoint.
  • If an upgrade is not possible immediately, block or remove the 'ysleadgen_get_captured_data' AJAX action by disabling the related hook or using a security plugin to filter unauthenticated AJAX requests.
  • Review any custom integrations or form usage to ensure they no longer expose captured data, adjusting plugin settings or coded callbacks as necessary.

Generated by OpenCVE AI on September 19, 2026 at 23:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Ysinnovations
Ysinnovations ys Leadgen – Popup Builder, Popup Maker & Form Builder For Wordpress | Lead Generation, Email Marketing, Sales, Conversions, Opt-ins & Subscribers
Vendors & Products Wordpress
Wordpress wordpress
Ysinnovations
Ysinnovations ys Leadgen – Popup Builder, Popup Maker & Form Builder For Wordpress | Lead Generation, Email Marketing, Sales, Conversions, Opt-ins & Subscribers

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it possible for unauthenticated attackers to retrieve all captured form submission data, including personally identifiable information (PII) such as names, email addresses, and message content submitted through YS LeadGen forms.
Title YS LeadGen – Popups, Opt-ins & Lead Capture <= 2.1.4 - Unauthenticated Information Disclosure in 'ysleadgen_get_captured_data' AJAX Action
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Wordpress Wordpress
Ysinnovations Ys Leadgen – Popup Builder, Popup Maker & Form Builder For Wordpress | Lead Generation, Email Marketing, Sales, Conversions, Opt-ins & Subscribers
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T13:51:19.555Z

Reserved: 2026-01-20T19:42:52.022Z

Link: CVE-2026-1255

cve-icon Vulnrichment

Updated: 2026-09-19T13:49:23.895Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T09:16:34.030

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-1255

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T23:45:08Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor