Executive brief
SiteLeads is a WordPress plugin that provides lead generation capabilities through a contact widget and AI chatbot. A vulnerability in versions up to 1.2.0 allows unauthenticated attackers to expose sensitive data such as user information and contact details, potentially compromising customer privacy and enabling account takeover or targeted phishing campaigns.
Technical details
The plugin contains a sensitive data exposure vulnerability (OWASP A3) accessible to unauthenticated users. The vulnerability affects all versions up to and including 1.2.0 and was patched in version 1.2.1. An attacker with network access (no authentication required) can retrieve private information including emails, passwords, or other contact data exposed through the widget or backend APIs. This likely stems from missing access controls or improper data filtering in the plugin's lead capture or retrieval endpoints.
Affected products
- SiteLeads Lead Generation Contact Widget & AI Chatbot <=1.2.0
Timeline
- 2026-08-24: disclosed
- 2026-08-24: patched: Version 1.2.1 and later