CVE-2026-1255: YS LeadGen – Popups, Opt-ins & Lead Capture <= 2.1.4 - Unauthenticated Information Disclosure in 'ysleadgen_get_captured_data' AJAX Action
The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgengetcaptureddata' AJAX action being accessible to unauthenticated users. This makes it possible for unauthenticated attackers to retrieve all captured form submission data, including personally identifiable information (PII) such as names, email addresses, and message content submitted through YS LeadGen forms.
Affected Software
Event History
Frequently Asked Questions
Who can access the exposed submission data?
Any unauthenticated remote attacker can invoke the affected AJAX action. No WordPress account, privileges, or user interaction are required.
What information may be disclosed?
An attacker can retrieve captured YS LeadGen form-submission data, including PII such as names, email addresses, and message content.
Which installations are affected?
All YS LeadGen plugin versions up to and including 2.1.4 are affected.