VYPR

YS LeadGen

by WordPress

CVEs (2)

  • CVE-2026-1255HigSep 19, 2026
    risk 0.42cvss 7.5epss 0.00

    The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it possible for unauthenticated attackers to…

  • CVE-2026-1256MedSep 19, 2026
    risk 0.35cvss 6.4epss 0.00

    The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to, and including, 2.1.4 due to missing capability checks on popup management actions. This makes it possible for…