Skip to content
Threat Feed
high advisory

Sensitive Information Exposure in YS LeadGen WordPress Plugin

The YS LeadGen plugin for WordPress versions 2.1.4 and earlier contains an unauthenticated information exposure vulnerability allowing the retrieval of form submission data.

CVE search metadata

CVE search record: CVE-2026-1255. Severity: high. CVSS: 7.5. KEV: no. Product: YS LeadGen (<= 2.1.4). Brief: Sensitive Information Exposure in YS LeadGen WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ys-leadgen-cve/

The YS LeadGen plugin for WordPress, in all versions up to and including 2.1.4, is susceptible to a sensitive information exposure vulnerability identified as CVE-2026-1255. The vulnerability stems from the improper implementation of the 'ysleadgen_get_captured_data' AJAX action, which fails to enforce authentication checks. This oversight allows unauthenticated, remote attackers to query the action and retrieve captured lead data stored by the plugin. The exposed data includes personally identifiable information (PII) such as user names, email addresses, and the content of messages submitted through forms managed by the plugin. This flaw facilitates unauthorized access to sensitive user data, presenting a significant risk to organizations collecting leads via the YS LeadGen plugin. Defenders should monitor web server logs for unauthorized requests targeting this specific AJAX endpoint.

Impact

The vulnerability poses a high risk to organizations using the affected versions of the YS LeadGen plugin. Successful exploitation leads to the unauthorized exfiltration of PII collected through website forms, potentially resulting in data breaches, regulatory non-compliance, and loss of user trust. Because the vulnerability is accessible to unauthenticated users, the barrier to exploitation is low.

Recommendation

  • Upgrade the YS LeadGen plugin to a version beyond 2.1.4 immediately to resolve CVE-2026-1255.
  • Monitor web server logs (e.g., Apache, Nginx, or IIS access logs) for HTTP requests targeting the '/wp-admin/admin-ajax.php' path with the 'action=ysleadgen_get_captured_data' parameter from suspicious or unauthorized IP addresses.
  • Review web application firewall (WAF) logs for abnormal spikes in traffic to AJAX endpoints associated with the YS LeadGen plugin.
  • Deactivate the YS LeadGen plugin if an immediate upgrade is not feasible until the vulnerability is mitigated.

Immediate actions

Check WordPress plugin inventory for vulnerable versions of YS LeadGen

IT Operations 24h

Threat Hunt

Search logs for 200 responses to ysleadgen_get_captured_data from external IP addresses

T1592 high high confidence hunt now

Data: webserver access logs

Mitigations

Update YS LeadGen to version 2.1.5 or newer

immediate IT Operations

CVE-2026-1255

Detection coverage 1

Detect CVE-2026-1255 Exploitation - Unauthenticated AJAX Data Retrieval

high

Detects unauthorized access to the YS LeadGen 'ysleadgen_get_captured_data' AJAX action via web server access logs.

sigma tactics: initial_access techniques: T1592 sources: webserver

Detection queries are available on the platform. Get full rules →