CVE-2025-31425

7.5

kamleshyadav · WP Lead Capturing Pages

A missing authorization vulnerability in the WP Lead Capturing Pages plugin allows unauthenticated attackers to exploit incorrectly configured access controls and cause a denial of service.

Executive summary

A critical missing authorization flaw in the WP Lead Capturing Pages plugin exposes the application to unauthenticated access control exploitation and potential service disruption.

Vulnerability

The plugin suffers from a missing authorization vulnerability (CWE-862) within the leadcapture component, which permits unauthenticated users to bypass intended access control security levels.

Business impact

Successful exploitation of this vulnerability can result in significant operational disruption, as the flaw allows unauthenticated actors to trigger a denial of service condition. With a CVSS score of 7.5, this high severity issue poses a substantial risk to service availability and system stability, necessitating prompt intervention to prevent unauthorized interaction with plugin functions.

Remediation

Immediate Action: Since no specific patch version is currently confirmed, administrators should immediately deactivate or remove the WP Lead Capturing Pages plugin until a secure update is released by the vendor.

Proactive Monitoring: Review web server and WordPress access logs for anomalous requests targeting the leadcapture endpoint or unexpected spikes in resource consumption.

Compensating Controls: Deploy a Web Application Firewall (WAF) with custom rules to block unauthorized requests to the plugin's endpoints, providing a virtual patch until the underlying software is remediated.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the potential for service disruption, organizations using this plugin must treat this vulnerability with high priority. Users are strongly advised to disable the plugin immediately and monitor the vendor's security advisories for the release of a patched version before re-enabling the component.

More kamleshyadav CVEs

Sources

Originally found and disclosed by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program, per the CVE Program record.