Impact
The YS LeadGen plugin for WordPress suffers from missing capability checks on several AJAX endpoints that allow authenticated users with Subscriber-level access and higher to create or manage popups. Because the plugin accepts user-supplied content without properly sanitizing it, an attacker can inject arbitrary JavaScript into a popup’s content. When a site visitor views the popup, the malicious script is executed in the visitor’s browser context, resulting in stored cross‑site scripting. The CVE description does not specify further consequences such as session hijacking, defacement, or theft of data, and those impacts are not explicitly documented in the official data.
Affected Systems
YS Innovations’ YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress is affected in all releases up to and including version 2.1.4. Users who have installed any of these versions or earlier are potentially vulnerable to the described stored XSS.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium level of risk. The EPSS score of less than 1% suggests that widespread exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a legitimate authenticated Subscriber or higher user and is carried out by sending crafted AJAX requests to the impacted endpoints. Once the malicious JavaScript is stored in a popup, it runs in the browser of each site visitor who views that popup.
OpenCVE Enrichment