← WordPress Vulnerabilities
WordPress security by component

Zoho CRM Lead Magnet

Zoho CRM Lead Magnet is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published Jan 23, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: zoho-crm-forms

CVE-2026-24595: Zoho CRM Lead Magnet: A security weakness

Zoho CRM Lead Magnet is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedJan 23, 2026
Safe version guidanceSee mitigation notes
Safe version
Jan 23, 2026 CVE-2026-24595
Zoho CRM Lead Magnet: A security weakness
Zoho CRM Lead Magnet is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Oct 17, 2024 CVE-2024-49297
Zoho CRM Lead Magnet: SQL injection
Zoho CRM Lead Magnet is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVDPending
Jul 20, 2024 CVE-2024-38696
Zoho CRM Lead Magnet: Cross-site scripting
Zoho CRM Lead Magnet is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Nov 09, 2022 CVE-2022-41978
Zoho Crm Forms: A security weakness
Zoho Crm Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVD6.5
Nov 26, 2019 CVE-2019-19306
Zoho Crm Forms: Cross-site scripting
Zoho Crm Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4