PT-2025-51149 · WordPress · Helloleads Crm Form Shortcode Wordpress Plugin

Khaled Alenazi

·

Published

2025-12-14

·

Updated

2025-12-14

·

CVE-2025-12696

CVSS v3.1
5.3
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions HelloLeads CRM Form Shortcode WordPress plugin versions through 1.0
Description The HelloLeads CRM Form Shortcode WordPress plugin does not properly verify authorization or include CSRF protection when resetting its settings. This allows unauthenticated users to reset the plugin’s settings.
Recommendations Update HelloLeads CRM Form Shortcode WordPress plugin to a version beyond 1.0.

Exploit

Fix

Related Identifiers

CVE-2025-12696

Affected Products

Helloleads Crm Form Shortcode Wordpress Plugin