Impact
The vulnerability allows unauthenticated actors to read sensitive lead data exposed by the Lead Generation Contact Widget & AI Chatbot plugin when its version is 1.2.0 or older. Because the plugin does not enforce proper access controls on the endpoints that return lead information, attackers can retrieve personal contact details and chatbot conversations without login. This results in a confidentiality breach of user data that the plugin captures, potentially exposing names, phone numbers, email addresses, and messaging history.
Affected Systems
This flaw affects the WordPress plugin “Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads” from Extend Themes. Any WordPress installation using plugin versions up to and including 1.2.0 is vulnerable. No newer versions are mentioned as affected.
Risk and Exploitability
With a CVSS score of 7.5, the vulnerability is considered high severity. The EPSS score is not available, and the record is not listed in the CISA KEV catalog, so the current exploit probability is uncertain. However, because authentication is not required and the data exposure can be achieved through simple HTTP requests to exposed endpoints, the likelihood of remote attackers exploiting this weakness is potentially significant in high‑traffic sites where the plugin stores lead information. Immediate patching is recommended to prevent further data compromise.
OpenCVE Enrichment