plugin

Lead Generated Vulnerabilities

2 known security issues reported for the Lead Generated WordPress plugin. Most recent disclosed Mar 22, 2023.

1 critical

Running Lead Generated on your site? Check whether your installed version is affected.

Scan your site free

Lead Generated [lead-generated] < 1.25 (closed)

unknown

[en] The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of the tve_api_form_submit action is passed to the PHP unserialize() function without being sanitized or verified, and as a result could lead to PHP object injection, wh...

Affected:
up to 1.25
Fixed in:
1.25
Disclosed:
Mar 22, 2023

CVE-2023-28667 on NVD →

Lead Generated <= 1.23 - Unauthenticated PHP Object Injection

critical

The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of the tve_api_form_submit action is passed to the PHP unserialize() function without being sanitized or verified, and as a result could lead to PHP object injection, which w...

CVSS:
9.8
Affected:
up to 1.23
Fixed in:
1.25
Disclosed:
Mar 20, 2023

CVE-2023-28667 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database