Skip to content
Noroxi

Zoho CRM Lead Magnet

zoho-crm-forms · plugin

Known security vulnerabilities for Zoho CRM Lead Magnet. Find out in seconds which version runs on your site with WP Lens.

5 known vulnerabilities

1 exploitable without logging in · latest Jan 23, 2026

Listed on wordpress.org · latest 1.8.2.3 · last updated Jun 9, 2026 · 3K+ installs

wordpress.org status checked on Oct 2, 2026

Vulnerabilities

  • CVE-2024-49297login required≤ 1.7.9.7

    WordPress Zoho CRM Lead Magnet plugin <= 1.7.9.7 - SQL Injection vulnerability

    High 8.5
  • CVE-2024-38696unauthenticated · needs a click≤ 1.7.8.8

    WordPress Zoho CRM Lead Magnet plugin <= 1.7.8.8 - Cross Site Scripting (XSS) vulnerability

    High 7.1
  • CVE-2022-41978subscriber+≤ 1.7.5.8

    WordPress Zoho CRM Lead Magnet plugin <= 1.7.5.8 - Auth. Arbitrary Options Update vulnerability

    Medium 6.5
  • CVE-2026-24595login required≤ 1.8.1.9

    WordPress Zoho CRM Lead Magnet plugin <= 1.8.1.9 - Broken Access Control vulnerability

    Medium 5.4
  • CVE-2019-19306login required

    The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.

    Medium 5.4

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory

Zoho CRM Lead Magnet — WordPress plugin vulnerabilities — Noroxi