plugin

Zoho Crm Forms Vulnerabilities

13 known security issues reported for the Zoho Crm Forms WordPress plugin. Most recent disclosed Jan 23, 2026.

1 high 5 medium

Running Zoho Crm Forms on your site? Check whether your installed version is affected.

Scan your site free

Zoho CRM Lead Magnet [zoho-crm-forms] <= 1.8.1.5 (unfixed)

unknown

[en] Missing Authorization vulnerability in zohocrm Zoho CRM Lead Magnet zoho-crm-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho CRM Lead Magnet: from n/a through <= 1.8.1.5.

Affected:
up to 1.8.1.5
Fix:
No patched version reported
Disclosed:
Jan 23, 2026

CVE-2026-24595 on NVD →

Zoho CRM Lead Magnet <= 1.8.1.9 - Missing Authorization

medium

The Zoho CRM Lead Magnet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.8.1.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.8.1.9
Fixed in:
1.8.2.0
Disclosed:
Jan 15, 2026

CVE-2026-24595 on NVD →

Zoho CRM Lead Magnet [zoho-crm-forms] < 1.7.9.8

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho CRM Zoho CRM Lead Magnet allows SQL Injection.This issue affects Zoho CRM Lead Magnet: from n/a through 1.7.9.0.

Affected:
up to 1.7.9.8
Fixed in:
1.7.9.8
Disclosed:
Oct 17, 2024

CVE-2024-49297 on NVD →

Zoho CRM Lead Magnet <= 1.7.9.7 - Authenticated (Contributor+) SQL Injection

medium

The Zoho CRM Lead Magnet plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.9.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level acc...

CVSS:
6.5
Affected:
up to 1.7.9.7
Fixed in:
1.7.9.8
Disclosed:
Oct 15, 2024

CVE-2024-49297 on NVD →

Zoho CRM Lead Magnet [zoho-crm-forms] < 1.7.8.9

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zoho CRM Zoho CRM Lead Magnet allows Reflected XSS.This issue affects Zoho CRM Lead Magnet: from n/a through 1.7.8.8.

Affected:
up to 1.7.8.9
Fixed in:
1.7.8.9
Disclosed:
Jul 20, 2024

CVE-2024-38696 on NVD →

Zoho CRM Lead Magnet <= 1.7.8.8 - Reflected Cross-Site Scripting

medium

The Zoho CRM Lead Magnet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.7.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can s...

CVSS:
6.1
Affected:
up to 1.7.8.8
Fixed in:
1.7.8.9
Disclosed:
Jul 11, 2024

CVE-2024-38696 on NVD →

Zoho CRM Lead Magnet [zoho-crm-forms] < 1.7.6.2

unknown

[en] Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress.

Affected:
up to 1.7.6.2
Fixed in:
1.7.6.2
Disclosed:
Nov 9, 2022

CVE-2022-41978 on NVD →

Zoho CRM Lead Magnet <= 1.7.5.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

high

The Zoho CRM Lead Magnet plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on one of its functions in versions up to, and including, 1.7.5.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update arbitrary options that can u...

CVSS:
8.3
Affected:
up to 1.7.5.8
Fixed in:
1.7.5.9
Disclosed:
Oct 27, 2022

CVE-2022-41978 on NVD →

Zoho CRM Lead Magnet [zoho-crm-forms] < 1.7.2.9

unknown

[en] A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website. The attack targets your application's users and not the application itself while using your application as the attack's vehicle. The XSS payload executes wheneve...

Affected:
up to 1.7.2.9
Fixed in:
1.7.2.9
Disclosed:
Oct 5, 2021

CVE-2021-33849 on NVD →

Zoho CRM Lead Magnet <= 1.7.2.4 - Cross-Site Scripting

medium

A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user&#8217;s browser while the browser is connected to a trusted website. The attack targets your application's users and not the application itself while using your application as the attack's vehicle. The XSS payload executes whenev...

CVSS:
6.4
Affected:
up to 1.7.2.4
Fixed in:
1.7.2.9
Disclosed:
Sep 1, 2021

CVE-2021-33849 on NVD →

Zoho CRM Lead Magnet [zoho-crm-forms] < 1.6.9.2

unknown

[en] The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.

Affected:
up to 1.6.9.2
Fixed in:
1.6.9.2
Disclosed:
Nov 26, 2019

CVE-2019-19306 on NVD →

Zoho CRM Lead Magnet [zoho-crm-forms] < 1.6.9.2

unknown

Authenticated Cross-Site Scripting (XSS) vulnerability found by Saran Baskar in WordPress Zoho CRM Lead Magnet plugin <=1.6.9.1

Affected:
up to 1.6.9.2
Fixed in:
1.6.9.2
Disclosed:
Oct 17, 2019

Zoho CRM Lead Magnet <= 1.6.9.1 - Reflected Cross-Site Scripting

medium

The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.

CVSS:
6.1
Affected:
up to 1.6.9.2
Fixed in:
1.6.9.2
Disclosed:
Oct 15, 2019

CVE-2019-19306 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database