---
id: CVE-2026-1255
title: >-
  The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information
  Exposure in all versions up to, and including, 2.1.4 due to the
  'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated
  users
summary: >-
  The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information
  Exposure in all versions up to, and including, 2.1.4 due to the
  'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated
  users. This makes it…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
vendor: ysinnovations
product: >-
  YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress | Lead
  Generation, Email Marketing, Sales, Conversions, Opt-Ins & Subscribers
affected:
  - >-
    ys_leadgen_popup_builder_popup_maker_form_builder_for_wordpress_lead_generation_email_marketing_sales_conversions_opt-ins_subscribers
    <= 2.1.4
published: '2026-09-19'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:33:33.387'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-1255'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/ysleadgen/tags/1.1.1/app/Controllers/Ajax.php#L65
    label: security@wordfence.com
  - url: 'https://plugins.trac.wordpress.org/changeset/3577391'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/66ca4e6a-e489-4c86-a9d4-1eb89c97cc1c?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
epss: 0.00295
epssPercentile: 0.22381
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-19T13:17:43.110631Z'
ingestedAt: '2026-09-19T09:00:39.472Z'
---

## Overview

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it possible for unauthenticated attackers to retrieve all captured form submission data, including personally identifiable information (PII) such as names, email addresses, and message content submitted through YS LeadGen forms.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
