Junglewise Threat Intelligence

CVE-2026-1256: YS LeadGen WordPress plugin authorization bypass and stored XSS

CVE-2026-1256 · Severity: medium · CVSS 6.4 · Published 2026-09-19

Executive brief

YS LeadGen is a WordPress plugin for creating lead capture popups. The plugin fails to properly restrict access to popup management functions, allowing authenticated users with basic subscriber permissions to create popups containing malicious JavaScript code. This code executes on any visitor's browser when the popup displays, potentially compromising sensitive information or redirecting users to malicious sites.

Technical details

The plugin lacks capability checks on multiple AJAX endpoints responsible for popup management, enabling privilege escalation from subscriber-level accounts. Authenticated attackers can inject arbitrary JavaScript into popup content via these unprotected endpoints, resulting in stored XSS that executes when the popup is rendered. The vulnerability affects all versions through 2.1.4 and requires authentication to exploit.

Affected products

  • YS Code YS LeadGen up to 2.1.4

Timeline

  • 2026-09-19: disclosed

References

Related threats