Wpleadplus develops a WordPress lead-capture plugin that integrates form and contact-management functionality into WordPress sites, a deployment context that exposes it to a broad user base across varying infrastructure maturity levels. The recurring vulnerability signal centers on cross-site scripting weaknesses in form input handling and page generation, a class endemic to web-facing plugins where user-supplied data flows into rendered HTML without sufficient sanitization. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpleadplus over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11509MEDIUM An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows remote attackers to upload page templates containing arbitrary JavaScript via the c37_wpl_import | Apr 7, 2020 | 6.1 | 22 | NO | NO |
CVE-2020-11508MEDIUM An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows logged-in users with minimal permissions to create or replace existing pages with a malicious pa | Apr 7, 2020 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpleadplus.
Media articles that mention a CVE ID that affects a product developed by Wpleadplus — matched by CVE ID, not by vendor name.