← WordPress Vulnerabilities
WordPress security by component

Lead Form Data Collection to CRM

Lead Form Data Collection to CRM is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jul 02, 2025; the highest CVE/CNA score is 8.8.

Plugin slug: wp-leads-builder-any-crm

CVE-2025-5692: Lead Form Data Collection to CRM: A security weakness

Lead Form Data Collection to CRM is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedJul 02, 2025
Safe version guidanceSee mitigation notes
Safe version
Jul 02, 2025 CVE-2025-5692
Lead Form Data Collection to CRM: A security weakness
Lead Form Data Collection to CRM is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.3
NVD4.3
May 23, 2025 CVE-2025-47690
Lead Form Data Collection to CRM: Privilege escalation or authentication bypass
Lead Form Data Collection to CRM is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Mar 27, 2025 CVE-2025-30810
Lead Form Data Collection to CRM: SQL injection
Lead Form Data Collection to CRM is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVDPending