CVE-2026-78268

7.5

Extend · Lead Generation Contact Widget & AI Chatbot (SiteLeads)

The SiteLeads WordPress plugin is vulnerable to unauthenticated sensitive data exposure, allowing unauthorized access to system information via the plugin's interface.

Executive summary

A critical unauthenticated information disclosure vulnerability in the SiteLeads WordPress plugin exposes sensitive system data, posing a significant risk of reconnaissance and potential further exploitation.

Vulnerability

The plugin suffers from an exposure of sensitive system information (CWE-497), which can be triggered by an unauthenticated attacker via a network-based request.

Business impact

Successful exploitation allows unauthorized parties to harvest sensitive system information, which facilitates targeted attacks against the hosting environment. Given the CVSS score of 7.5, this high-severity flaw requires immediate attention to prevent the compromise of infrastructure details that could lead to full system takeover.

Remediation

Immediate Action: Update the SiteLeads plugin to version 1.2.1 or later immediately.

Proactive Monitoring: Review web server access logs for unusual traffic patterns or unauthorized requests directed at plugin-specific endpoints.

Compensating Controls: Implement a Web Application Firewall (WAF) rule to block unauthorized access to the plugin directory and sensitive API endpoints until the update is applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The vulnerability presents a clear risk to data confidentiality and infrastructure security. Administrators must prioritize updating to version 1.2.1 to close this exposure vector and prevent potential reconnaissance activities.