{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ys-leadgen--2.1.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ys_leadgen_project:ys_leadgen:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-1255"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["YS LeadGen (\u003c= 2.1.4)"],"_cs_severities":["high"],"_cs_tags":["web-application","sensitive-information-exposure","wordpress"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe YS LeadGen plugin for WordPress, in all versions up to and including 2.1.4, is susceptible to a sensitive information exposure vulnerability identified as CVE-2026-1255. The vulnerability stems from the improper implementation of the 'ysleadgen_get_captured_data' AJAX action, which fails to enforce authentication checks. This oversight allows unauthenticated, remote attackers to query the action and retrieve captured lead data stored by the plugin. The exposed data includes personally identifiable information (PII) such as user names, email addresses, and the content of messages submitted through forms managed by the plugin. This flaw facilitates unauthorized access to sensitive user data, presenting a significant risk to organizations collecting leads via the YS LeadGen plugin. Defenders should monitor web server logs for unauthorized requests targeting this specific AJAX endpoint.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a high risk to organizations using the affected versions of the YS LeadGen plugin. Successful exploitation leads to the unauthorized exfiltration of PII collected through website forms, potentially resulting in data breaches, regulatory non-compliance, and loss of user trust. Because the vulnerability is accessible to unauthenticated users, the barrier to exploitation is low.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the YS LeadGen plugin to a version beyond 2.1.4 immediately to resolve CVE-2026-1255.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs (e.g., Apache, Nginx, or IIS access logs) for HTTP requests targeting the '/wp-admin/admin-ajax.php' path with the 'action=ysleadgen_get_captured_data' parameter from suspicious or unauthorized IP addresses.\u003c/li\u003e\n\u003cli\u003eReview web application firewall (WAF) logs for abnormal spikes in traffic to AJAX endpoints associated with the YS LeadGen plugin.\u003c/li\u003e\n\u003cli\u003eDeactivate the YS LeadGen plugin if an immediate upgrade is not feasible until the vulnerability is mitigated.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-19T10:11:28Z","date_published":"2026-09-19T10:11:28Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ys-leadgen-cve/","summary":"The YS LeadGen plugin for WordPress versions 2.1.4 and earlier contains an unauthenticated information exposure vulnerability allowing the retrieval of form submission data.","title":"Sensitive Information Exposure in YS LeadGen WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-ys-leadgen-cve/"}],"language":"en","title":"CraftedSignal Threat Feed - YS LeadGen (\u003c= 2.1.4)","version":"https://jsonfeed.org/version/1.1"}