wp2leads vulnerabilities
CVEs whose affected-version data names the wp2leads package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-25434High· 8.5Subscriber SQL Injection in WP2LEADS <= 3.5.7 versions.
Subscriber SQL Injection in WP2LEADS <= 3.5.7 versions.
▾ TwilightTobias @Saleswonder.biz · wp2leadsvia NVD
CVE-2026-25433High· 7.1Subscriber Broken Access Control in WP2LEADS <= 3.5.7 versions.
Subscriber Broken Access Control in WP2LEADS <= 3.5.7 versions.
▾ TwilightTobias @Saleswonder.biz · wp2leadsvia NVD