PatchSiren

ysinnovations CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ysinnovations CVE published 2026-09-19

CVE-2026-1256

The YS LeadGen plugin for WordPress has a vulnerability that allows authenticated attackers with Subscriber-level access to create arbitrary popups and inject malicious JavaScript, leading to Stored Cross-Site Scripting (XSS). This vulnerability exists in all versions up to and including 2.1.4 due to missing capability checks on popup management actions. Defenders responsible for WordPress installations w [truncated]

HIGH ysinnovations CVE published 2026-09-19

CVE-2026-1255

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This makes it possible for unauthenticated attackers to retrieve all captured form submission data, including personally identifiable information (PII) such as names, email addresses, and message content submitted through YS LeadGen forms.