What the vulnerability does
01Description
Missing Authorization vulnerability in wishfulthemes Email Capture & Lead Generation email-capture-lead-generation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Email Capture & Lead Generation: from n/a through <= 1.0.2.
Explanation of Vulnerability in Simple Terms
02Summary
Email Capture & Lead Generation versions 1.0.2 and earlier lack proper authorization checks, allowing authenticated users to modify data they should not have access to. An attacker with a low-privilege account can alter information without restriction. The vulnerability affects integrity but not confidentiality or availability. Update to a version newer than 1.0.2.
What an attacker can do
03Attacker Capabilities
Modify or alter data in the plugin without proper permission checks.
Potential impact on your site
04Site Impact
Low-privilege users can change plugin data they should not be able to access, risking data integrity.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege authenticated account on the site.
Key dates
06Disclosure timeline
January 16, 2025
CVE published
May 11, 2026
Record updated