CVE-2025-12696: Unknown Helloleads CRM Form Shortcode
Medium severity, CVSS 5.3. EPSS: 0.1% chance of exploitation in the next 30 days.
The HelloLeads CRM Form Shortcode WordPress plugin through 1.0 does not have authorisation and CSRF check when resetting its settings, allowing unauthenticated users to reset them
Affected products
- Unknown Helloleads CRM Form Shortcode: up to and including 1.0
Published 2025-12-14. Last modified 2026-10-07.