Zoho CRM Lead Magnet [zoho-crm-forms] <= 1.8.1.5 (unfixed)
unknown
[en] Missing Authorization vulnerability in zohocrm Zoho CRM Lead Magnet zoho-crm-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho CRM Lead Magnet: from n/a through <= 1.8.1.5.
- Affected:
- up to 1.8.1.5
- Fix:
- No patched version reported
- Disclosed:
- Jan 23, 2026
CVE-2026-24595 on NVD →
Zoho CRM Lead Magnet <= 1.8.1.9 - Missing Authorization
medium
The Zoho CRM Lead Magnet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.8.1.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.8.1.9
- Fixed in:
- 1.8.2.0
- Disclosed:
- Jan 15, 2026
CVE-2026-24595 on NVD →
Zoho CRM Lead Magnet [zoho-crm-forms] < 1.7.9.8
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho CRM Zoho CRM Lead Magnet allows SQL Injection.This issue affects Zoho CRM Lead Magnet: from n/a through 1.7.9.0.
- Affected:
- up to 1.7.9.8
- Fixed in:
- 1.7.9.8
- Disclosed:
- Oct 17, 2024
CVE-2024-49297 on NVD →
Zoho CRM Lead Magnet <= 1.7.9.7 - Authenticated (Contributor+) SQL Injection
medium
The Zoho CRM Lead Magnet plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.9.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level acc...
- CVSS:
- 6.5
- Affected:
- up to 1.7.9.7
- Fixed in:
- 1.7.9.8
- Disclosed:
- Oct 15, 2024
CVE-2024-49297 on NVD →
Zoho CRM Lead Magnet [zoho-crm-forms] < 1.7.8.9
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zoho CRM Zoho CRM Lead Magnet allows Reflected XSS.This issue affects Zoho CRM Lead Magnet: from n/a through 1.7.8.8.
- Affected:
- up to 1.7.8.9
- Fixed in:
- 1.7.8.9
- Disclosed:
- Jul 20, 2024
CVE-2024-38696 on NVD →
Zoho CRM Lead Magnet <= 1.7.8.8 - Reflected Cross-Site Scripting
medium
The Zoho CRM Lead Magnet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.7.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can s...
- CVSS:
- 6.1
- Affected:
- up to 1.7.8.8
- Fixed in:
- 1.7.8.9
- Disclosed:
- Jul 11, 2024
CVE-2024-38696 on NVD →
Zoho CRM Lead Magnet [zoho-crm-forms] < 1.7.6.2
unknown
[en] Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress.
- Affected:
- up to 1.7.6.2
- Fixed in:
- 1.7.6.2
- Disclosed:
- Nov 9, 2022
CVE-2022-41978 on NVD →
Zoho CRM Lead Magnet <= 1.7.5.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
high
The Zoho CRM Lead Magnet plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on one of its functions in versions up to, and including, 1.7.5.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update arbitrary options that can u...
- CVSS:
- 8.3
- Affected:
- up to 1.7.5.8
- Fixed in:
- 1.7.5.9
- Disclosed:
- Oct 27, 2022
CVE-2022-41978 on NVD →
Zoho CRM Lead Magnet [zoho-crm-forms] < 1.7.2.9
unknown
[en] A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website. The attack targets your application's users and not the application itself while using your application as the attack's vehicle. The XSS payload executes wheneve...
- Affected:
- up to 1.7.2.9
- Fixed in:
- 1.7.2.9
- Disclosed:
- Oct 5, 2021
CVE-2021-33849 on NVD →
Zoho CRM Lead Magnet <= 1.7.2.4 - Cross-Site Scripting
medium
A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website. The attack targets your application's users and not the application itself while using your application as the attack's vehicle. The XSS payload executes whenev...
- CVSS:
- 6.4
- Affected:
- up to 1.7.2.4
- Fixed in:
- 1.7.2.9
- Disclosed:
- Sep 1, 2021
CVE-2021-33849 on NVD →
Zoho CRM Lead Magnet [zoho-crm-forms] < 1.6.9.2
unknown
[en] The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.
- Affected:
- up to 1.6.9.2
- Fixed in:
- 1.6.9.2
- Disclosed:
- Nov 26, 2019
CVE-2019-19306 on NVD →
Zoho CRM Lead Magnet [zoho-crm-forms] < 1.6.9.2
unknown
Authenticated Cross-Site Scripting (XSS) vulnerability found by Saran Baskar in WordPress Zoho CRM Lead Magnet plugin <=1.6.9.1
- Affected:
- up to 1.6.9.2
- Fixed in:
- 1.6.9.2
- Disclosed:
- Oct 17, 2019
Zoho CRM Lead Magnet <= 1.6.9.1 - Reflected Cross-Site Scripting
medium
The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.
- CVSS:
- 6.1
- Affected:
- up to 1.6.9.2
- Fixed in:
- 1.6.9.2
- Disclosed:
- Oct 15, 2019
CVE-2019-19306 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database