Executive brief
leadlovers forms is a WordPress plugin used to create and manage lead generation forms. A security flaw in the plugin allows unauthorized individuals to bypass intended access controls. This could potentially allow an attacker to modify form settings or access data they should not be able to see, compromising the integrity of marketing workflows.
Technical details
The leadlovers forms plugin for WordPress (versions up to and including 1.0.2) contains a missing authorization vulnerability (CWE-862). The flaw stems from incorrectly configured access control security levels within the plugin's functional components. An unauthenticated remote attacker can exploit this by sending crafted requests to the affected site, potentially allowing them to execute functions or access data intended for higher-privileged users. As of the advisory date, no official patch has been released, and users are advised to monitor for updates or seek alternative mitigations.
Affected products
- leadlovers leadlovers forms <= 1.0.2
Timeline
- 2026-01-17: other: Vulnerability reported by NumeX
- 2026-02-16: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published