CVE-2025-31425
7.5kamleshyadav · WP Lead Capturing Pages
A missing authorization vulnerability in the WP Lead Capturing Pages plugin allows unauthenticated attackers to exploit incorrectly configured access controls and cause a denial of service.
Executive summary
A critical missing authorization flaw in the WP Lead Capturing Pages plugin exposes the application to unauthenticated access control exploitation and potential service disruption.
Vulnerability
The plugin suffers from a missing authorization vulnerability (CWE-862) within the leadcapture component, which permits unauthenticated users to bypass intended access control security levels.
Business impact
Successful exploitation of this vulnerability can result in significant operational disruption, as the flaw allows unauthenticated actors to trigger a denial of service condition. With a CVSS score of 7.5, this high severity issue poses a substantial risk to service availability and system stability, necessitating prompt intervention to prevent unauthorized interaction with plugin functions.
Remediation
Immediate Action: Since no specific patch version is currently confirmed, administrators should immediately deactivate or remove the WP Lead Capturing Pages plugin until a secure update is released by the vendor.
Proactive Monitoring: Review web server and WordPress access logs for anomalous requests targeting the leadcapture endpoint or unexpected spikes in resource consumption.
Compensating Controls: Deploy a Web Application Firewall (WAF) with custom rules to block unauthorized requests to the plugin's endpoints, providing a virtual patch until the underlying software is remediated.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the potential for service disruption, organizations using this plugin must treat this vulnerability with high priority. Users are strongly advised to disable the plugin immediately and monitor the vendor's security advisories for the release of a patched version before re-enabling the component.
More kamleshyadav CVEs
Sources
Originally found and disclosed by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program, per the CVE Program record.