---
id: CVE-2026-1256
title: >-
  The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and
  Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to,
  and including, 2.1.4 due to missing capability checks on popup management
  action…
summary: >-
  The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and
  Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to,
  and including, 2.1.4 due to missing capability checks on popup management
  action…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: ysinnovations
product: >-
  YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress | Lead
  Generation, Email Marketing, Sales, Conversions, Opt-Ins & Subscribers
affected:
  - >-
    ys_leadgen_popup_builder_popup_maker_form_builder_for_wordpress_lead_generation_email_marketing_sales_conversions_opt-ins_subscribers
    <= 2.1.4
published: '2026-09-19'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:33:33.387'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-1256'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/ysleadgen/tags/1.1.1/app/Controllers/Ajax.php#L36
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/ysleadgen/tags/1.1.1/app/Controllers/Ajax.php#L37
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/ysleadgen/tags/1.1.1/app/Controllers/Ajax.php#L38
    label: security@wordfence.com
  - url: 'https://plugins.trac.wordpress.org/changeset/3577391'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/b62b8619-4348-4cf7-a572-aa6df20bdc3a?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
epss: 0.00204
epssPercentile: 0.10678
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-19T13:17:19.796590Z'
ingestedAt: '2026-09-19T09:00:39.471Z'
---

## Overview

The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to, and including, 2.1.4 due to missing capability checks on popup management actions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary popups and inject malicious JavaScript that executes when the popup is displayed, leading to Stored XSS.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
