CVE-2026-25433: WordPress WP2LEADS plugin <= 3.5.7 - Broken Access Control vulnerability
Published Oct 6, 2026
·Updated
Subscriber Broken Access Control in WP2LEADS <= 3.5.7 versions.
Affected Software
1 affected component
WordPress WP2LEADS Plugin<=3.5.7
Event History
Oct 6, 2026
CVE Published
via MITRE·08:33 AM
Data Sourced
via MITRE·08:33 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
An attacker needs an existing account with Subscriber-level privileges. The vulnerability is remotely exploitable and does not require user interaction.
2
What is the potential impact if exploited?
Successful exploitation could expose highly sensitive information and cause a limited availability impact. The provided data does not indicate an integrity impact.
3
Which plugin versions are affected?
WP2LEADS plugin versions 3.5.7 and earlier are affected.