CVE-2026-1256
Received Received - Intake

Authorization Bypass and Stored XSS in YS LeadGen WordPress Plugin

Vulnerability report for CVE-2026-1256, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-19

Last updated on: 2026-09-19

Assigner: Wordfence

Description

The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to, and including, 2.1.4 due to missing capability checks on popup management actions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary popups and inject malicious JavaScript that executes when the popup is displayed, leading to Stored XSS.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-19
Last Modified
2026-09-19
Generated
2026-09-20
AI Q&A
2026-09-20
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ys_leadgen plugin to 2.1.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The YS LeadGen WordPress plugin up to version 2.1.4 has an authorization bypass and stored cross-site scripting vulnerability. It lacks proper capability checks on popup management AJAX endpoints, allowing authenticated users with Subscriber access or higher to create popups and inject malicious JavaScript. This stored XSS executes when the popup is displayed.

Detection Guidance

To detect this vulnerability, check for unauthorized popup creation or suspicious JavaScript injections in WordPress sites using the YS LeadGen plugin versions up to 2.1.4. Inspect browser console logs for unexpected scripts and review plugin files for unauthorized modifications. No specific commands are provided in the context.

Impact Analysis

An attacker could inject malicious scripts into your WordPress site, potentially stealing user data, session cookies, or redirecting visitors to harmful sites. It may also allow unauthorized modifications to site content or defacement.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. Non-compliance may result in legal penalties, fines, or reputational damage.

Mitigation Strategies
  • Update the YS LeadGen plugin to the latest version beyond 2.1.4 if available.
  • Remove or disable the YS LeadGen plugin if no update is available.
  • Review and remove any unauthorized popups or injected scripts from the WordPress database.
  • Monitor user accounts with Subscriber-level access or higher for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-1256. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart