PatchSiren

leadlovers CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM leadlovers CVE published 2026-04-08

CVE-2026-39657

A Missing Authorization vulnerability exists in the leadlovers forms plugin, affecting versions from n/a through 1.0.2. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels, with a CVSS score of 5.3 and a severity of MEDIUM. The vulnerability could allow unauthorized access to sensitive data or functionality. The leadlovers forms plugin has a CWE-862 vulnerability. Users [truncated]