Description
The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to, and including, 2.1.4 due to missing capability checks on popup management actions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary popups and inject malicious JavaScript that executes when the popup is displayed, leading to Stored XSS.
Published: 2026-09-19
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The YS LeadGen plugin for WordPress suffers from missing capability checks on several AJAX endpoints that allow authenticated users with Subscriber-level access and higher to create or manage popups. Because the plugin accepts user-supplied content without properly sanitizing it, an attacker can inject arbitrary JavaScript into a popup’s content. When a site visitor views the popup, the malicious script is executed in the visitor’s browser context, resulting in stored cross‑site scripting. The CVE description does not specify further consequences such as session hijacking, defacement, or theft of data, and those impacts are not explicitly documented in the official data.

Affected Systems

YS Innovations’ YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress is affected in all releases up to and including version 2.1.4. Users who have installed any of these versions or earlier are potentially vulnerable to the described stored XSS.

Risk and Exploitability

The CVSS score of 6.4 indicates a medium level of risk. The EPSS score of less than 1% suggests that widespread exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a legitimate authenticated Subscriber or higher user and is carried out by sending crafted AJAX requests to the impacted endpoints. Once the malicious JavaScript is stored in a popup, it runs in the browser of each site visitor who views that popup.

Generated by OpenCVE AI on September 19, 2026 at 23:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade YS LeadGen to a version newer than 2.1.4 where the missing capability checks have been added.
  • Restrict the Subscriber role from accessing popup management functionalities by adjusting user capabilities or role definitions in WordPress.
  • If immediate upgrade is not possible, disable the vulnerable AJAX endpoints via server‑side rules or by installing a security plugin that blocks unauthorized AJAX calls.

Generated by OpenCVE AI on September 19, 2026 at 23:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Ysinnovations
Ysinnovations ys Leadgen – Popup Builder, Popup Maker & Form Builder For Wordpress | Lead Generation, Email Marketing, Sales, Conversions, Opt-ins & Subscribers
Vendors & Products Wordpress
Wordpress wordpress
Ysinnovations
Ysinnovations ys Leadgen – Popup Builder, Popup Maker & Form Builder For Wordpress | Lead Generation, Email Marketing, Sales, Conversions, Opt-ins & Subscribers

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to, and including, 2.1.4 due to missing capability checks on popup management actions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary popups and inject malicious JavaScript that executes when the popup is displayed, leading to Stored XSS.
Title YS LeadGen – Popups, Opt-ins & Lead Capture <= 2.1.4 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via User Input
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Ysinnovations Ys Leadgen – Popup Builder, Popup Maker & Form Builder For Wordpress | Lead Generation, Email Marketing, Sales, Conversions, Opt-ins & Subscribers
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T13:51:19.044Z

Reserved: 2026-01-20T19:48:06.226Z

Link: CVE-2026-1256

cve-icon Vulnrichment

Updated: 2026-09-19T13:48:46.719Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T09:16:34.163

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-1256

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')