Sceawere

Vulnerability Detail

CVE-2026-25433UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP2LEADS Subscriber Broken Access Control

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
16h ago
Vendor
Tobias @Saleswonder.biz
Product
WP2LEADS
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Subscriber Broken Access Control in WP2LEADS <= 3.5.7 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-06T09:17:41.777Z",
  "pubdate": "2026-10-06T09:17:41.777Z",
  "executiveSummary": "The WP2LEADS plugin, in versions up to 3.5.7, is susceptible to a broken access control vulnerability. This security flaw allows authenticated users with low-level privileges, specifically the Subscriber role, to perform unauthorized actions or access sensitive functionality restricted to higher-privileged administrators.\nThe vulnerability stems from improper capability checks within the plugin's architectural design. By failing to validate the user's role before executing sensitive administrative functions, the application exposes an attack surface that can be leveraged to manipulate plugin settings, modify lead data, or perform unauthorized administrative operations.\nThe impact of this vulnerability is significant, as it grants unauthorized individuals the ability to alter system configurations, potentially leading to unauthorized data exposure or malicious plugin behavior. An attacker requires a valid account on the WordPress installation with at least Subscriber-level access to initiate the exploit. No specialized technical infrastructure is required beyond basic knowledge of the WordPress plugin interface and request interception tools to craft the malicious payloads.",
  "technicalDetails": "The root cause of this vulnerability lies in the insufficient implementation of access control checks (authorization logic) within the plugin’s request handling functions. In the WordPress security model, plugin developers are expected to utilize functions like current_user_can() to ensure that only authorized users, typically those with the 'manage_options' or 'administrator' capabilities, can access sensitive hooks, AJAX actions, or administrative backend menus.\nIn WP2LEADS versions 3.5.7 and below, several administrative actions do not perform adequate validation to verify that the requesting user possesses the necessary privileges. The vulnerable component consists of the plugin's backend routing and event handler functions that process user requests. When an administrative request is dispatched, the code fails to verify the authorization level before executing the associated logic.\nThe attack flow proceeds as follows: First, an attacker authenticates to the WordPress instance using a standard Subscriber account. Second, the attacker identifies the specific AJAX action or administrative endpoint handled by the WP2LEADS plugin that lacks proper authorization checks. Third, the attacker transmits a crafted HTTP request (often a POST request containing the target action parameter) to the WordPress admin-ajax.php file or the specific plugin endpoint. Because the plugin logic relies on implicit trust of the requesting user rather than explicit role-based access control, the server processes the request as if it originated from an authorized administrator. Consequently, the attacker can execute sensitive administrative functions, such as updating plugin settings, deleting records, or exporting sensitive lead information collected by the system.\nThis vulnerability is particularly severe because the plugin fails to define a consistent security policy across its administrative interface. The lack of granular privilege validation means that any logged-in user can trigger server-side code execution intended strictly for site administrators. Because the vulnerability exists within the application layer of the plugin, the risk is persistent regardless of the network environment, as long as the WordPress installation allows user registration or provides credentials to untrusted parties. Post-exploitation, an attacker may leverage this access to inject malicious scripts, alter site behavior, or facilitate secondary attacks by reconfiguring the plugin to report data to external, attacker-controlled servers."
}
CVE-2026-25433: WP2LEADS Subscriber Broken Access Control (HIGH Severity, CVSS: 7.1) | Sceawere