Executive brief
The YS LeadGen plugin for WordPress contains a vulnerability that allows anyone on the internet to retrieve sensitive form submission data without logging in. An attacker can access all captured information including names, email addresses, and message content submitted through YS LeadGen forms, leading to exposure of personally identifiable information and potential privacy breaches.
Technical details
The 'ysleadgen_get_captured_data' AJAX action lacks proper authentication checks, allowing unauthenticated attackers to invoke it and retrieve all stored form submission data from the plugin's database. This information exposure affects all versions up to 2.1.4 and requires only network access to the WordPress installation; no user interaction or prior authentication is necessary.
Affected products
- YS Code YS LeadGen up to and including 2.1.4
Timeline
- 2026-09-19: disclosed