DECIPHERU · INTELLIGENCECVE

ByJulian Calvo, Ed.D., M.S.Founder, DecipherU
HIGHCVESeptember 19, 2026

CVE-2026-1255, The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Expos...

Source: nvd.nist.gov (CVE-2026-1255) · September 19, 2026
DecipherU Intelligence aggregates cybersecurity developments from government databases, official filings, and authoritative sources. The summary below is written by DecipherU and does not represent the views of the original source. For full details, follow the source link.

Summary

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it possible for unauthenticated attackers to retrieve all captured form submission data, including personally identifiable information (PII) such as names, email addresses, and message content submitted through YS LeadGen forms.

Relevant Roles

incident-responder

For the full cve details, visit the original source.

Read Original Source: nvd.nist.gov
Source: nvd.nist.gov, September 19, 2026. This summary is DecipherU's original writing. For complete details, follow the source link above. This page is for informational purposes only and does not constitute security advice.

Sources

  1. NIST National Vulnerability Database (NVD) · Authoritative CVE records and CVSS scoring.
  2. CISA Advisories · Public-domain US Cybersecurity and Infrastructure Security Agency alerts.
  3. DecipherU Live Feeds · DecipherU aggregates and curates these cybersecurity intelligence items.
Last verified: September 19, 2026?Report an inaccuracy