WP2LEADS | WordPress und KlickTipp einfach verbinden – WooCommerce und KlickTipp einfach verbinden [wp2leads] < 3.5.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team Tobias WP2LEADS allows Reflected XSS. This issue affects WP2LEADS: from n/a through 3.5.0.
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.1
- Disclosed:
- Jun 17, 2025
CVE-2025-49316 on NVD →
WP2LEADS <= 3.5.0 - Reflected Cross-Site Scripting
medium
The WP2LEADS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...
- CVSS:
- 6.1
- Affected:
- up to 3.5.0
- Fixed in:
- 3.5.1
- Disclosed:
- Jun 15, 2025
CVE-2025-49316 on NVD →
WP2LEADS <= 3.5.0 - Cross-Site Request Forgery
medium
The WP2LEADS | WordPress und KlickTipp einfach verbinden – WooCommerce und KlickTipp einfach verbinden plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthentic...
- CVSS:
- 4.3
- Affected:
- up to 3.5.0
- Fixed in:
- 3.5.1
- Disclosed:
- May 15, 2025
CVE-2025-32922 on NVD →
WP2LEADS | WordPress und KlickTipp einfach verbinden – WooCommerce und KlickTipp einfach verbinden [wp2leads] <= 3.5.0 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Tobias WP2LEADS allows Stored XSS.This issue affects WP2LEADS: from n/a through 3.5.0.
- Affected:
- up to 3.5.0
- Fix:
- No patched version reported
- Disclosed:
- May 15, 2025
CVE-2025-32922 on NVD →
WP2LEADS | WordPress und KlickTipp einfach verbinden – WooCommerce und KlickTipp einfach verbinden [wp2leads] < 3.4.7
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team Tobias WP2LEADS allows Reflected XSS. This issue affects WP2LEADS: from n/a through 3.4.5.
- Affected:
- up to 3.4.7
- Fixed in:
- 3.4.7
- Disclosed:
- Apr 1, 2025
CVE-2025-30827 on NVD →
WP2LEADS <= 3.4.5 - Reflected Cross-Site Scripting
medium
The WP2LEADS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...
- CVSS:
- 6.1
- Affected:
- up to 3.4.5
- Fixed in:
- 3.4.7
- Disclosed:
- Mar 27, 2025
CVE-2025-30827 on NVD →
WP2LEADS | WordPress und KlickTipp einfach verbinden – WooCommerce und KlickTipp einfach verbinden [wp2leads] < 3.3.4
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team Tobias WP2LEADS allows Reflected XSS. This issue affects WP2LEADS: from n/a through 3.3.3.
- Affected:
- up to 3.3.4
- Fixed in:
- 3.3.4
- Disclosed:
- Feb 14, 2025
CVE-2025-24565 on NVD →
WP2LEADS | WordPress und KlickTipp einfach verbinden – WooCommerce und KlickTipp einfach verbinden [wp2leads] < 3.4.3
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder.biz Team WP2LEADS allows Reflected XSS.This issue affects WP2LEADS: from n/a through 3.4.2.
- Affected:
- up to 3.4.3
- Fixed in:
- 3.4.3
- Disclosed:
- Jan 13, 2025
CVE-2024-56065 on NVD →
WP2LEADS <= 3.4.2 - Reflected Cross-Site Scripting
medium
The WP2LEADS | WordPress und KlickTipp einfach verbinden – WooCommerce und KlickTipp einfach verbinden plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated...
- CVSS:
- 6.1
- Affected:
- up to 3.4.2
- Fixed in:
- 3.4.3
- Disclosed:
- Jan 3, 2025
CVE-2024-56065 on NVD →
WP2LEADS <= 3.3.3 - Reflected Cross-Site Scripting
medium
The WP2LEADS | WordPress und KlickTipp einfach verbinden – WooCommerce und KlickTipp einfach verbinden plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated...
- CVSS:
- 6.1
- Affected:
- up to 3.3.3
- Fixed in:
- 3.3.4
- Disclosed:
- Dec 24, 2024
CVE-2025-24565 on NVD →
WP2LEADS <= 3.2.7 - Missing Authorization
medium
The WP2LEADS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions such as import_maps in versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform several unauthorized actions.
- CVSS:
- 4.3
- Affected:
- up to 3.2.7
- Fixed in:
- 3.2.8
- Disclosed:
- Apr 8, 2024
CVE-2024-31375 on NVD →
WP2LEADS | WordPress und KlickTipp einfach verbinden – WooCommerce und KlickTipp einfach verbinden [wp2leads] < 3.2.8
unknown
[en] Missing Authorization vulnerability in Saleswonder.Biz Team WP2LEADS.This issue affects WP2LEADS: from n/a through 3.2.7.
- Affected:
- up to 3.2.8
- Fixed in:
- 3.2.8
- Disclosed:
- Apr 8, 2024
CVE-2024-31375 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database