CVE Database
/

CVE-2025-12696

Back to search

CVE-2025-12696

Published: Dec 14, 2025

Modified: Apr 2, 2026

PUBLISHED

Description

The HelloLeads CRM Form Shortcode WordPress plugin through 1.0 does not have authorisation and CSRF check when resetting its settings, allowing unauthenticated users to reset them

VendorProductVersions

Unknown

HelloLeads CRM Form Shortcode

affected
0 - <= 1.0

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2025-12696 - Security Vulnerability | QwikSec