Executive brief
The Leadrebel plugin for WordPress, which is used for lead generation and tracking, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to bypass intended security levels and potentially access information or perform actions they should not be able to. If exploited, this could lead to the exposure of internal data or unauthorized changes to the plugin's configuration.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Leadrebel plugin for WordPress through version 1.0.2. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before granting access to specific functions or data. An unauthenticated remote attacker can exploit this by sending crafted requests to the affected component, potentially leading to unauthorized data disclosure or the execution of restricted actions. As of the latest advisory, no official patch has been released, and users are advised to monitor for updates from the developer.
Affected products
- leadrebel Leadrebel <= 1.0.2
Timeline
- 2026-01-19: other: Vulnerability reported by researcher Nabil Irawan
- 2026-02-18: advisory: Initial advisory published by Patchstack
- 2026-04-08: disclosed: CVE published to the National Vulnerability Database (NVD)