Brilliant Web-to-Lead for Salesforce Security & Risk Analysis

wordpress.org/plugins/salesforce-wordpress-to-lead

Brilliant Web-to-Lead for Salesforce creates a solid integration between your WordPress install(s) and your Salesforce.com account!

2K active installs v2.7.3.9 PHP 7.4+ WP 5.0+ Updated Feb 24, 2022
case-to-leadcontact-formcontactformcrmweb-to-lead
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 5, 2025
Safety Verdict

Is Brilliant Web-to-Lead for Salesforce Safe to Use in 2026?

Use With Caution

Score 63/100

Brilliant Web-to-Lead for Salesforce has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 5, 2025Updated 4yr ago
Risk Assessment

The Salesforce WordPress to Lead plugin, version 2.7.3.9, exhibits a mixed security posture. While the static analysis highlights some good practices, such as 100% of SQL queries using prepared statements and a high percentage of properly escaped output, significant concerns remain. The lack of any nonce checks or capability checks for its single shortcode is a notable weakness, as this represents a potential entry point without proper authorization or validation. Furthermore, the plugin has a history of vulnerabilities, with one unpatched medium severity CVE and a past incident involving Cross-Site Request Forgery (CSRF). The presence of two external HTTP requests also warrants scrutiny, as these could be exploited if not handled securely.

The taint analysis reveals two flows with unsanitized paths, which, while not classified as critical or high severity in this analysis, indicate potential areas where user-supplied data could be processed insecurely. The vulnerability history, particularly the ongoing unpatched medium CVE and the past CSRF issue, suggests a recurring pattern of security oversights. Although there are strengths in its query and output handling, the identified lack of checks on its shortcode and the unaddressed historical vulnerabilities present tangible risks that users should be aware of.

Key Concerns

  • Unpatched medium severity CVE
  • Shortcode lacks nonce and capability checks
  • Flows with unsanitized paths
  • External HTTP requests
Vulnerabilities
1

Brilliant Web-to-Lead for Salesforce Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58809medium · 4.3Cross-Site Request Forgery (CSRF)

To Lead For Salesforce <= 2.7.3.9 - Cross-Site Request Forgery

Sep 5, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Brilliant Web-to-Lead for Salesforce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
21 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

95% escaped22 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
salesforce_form_shortcode (salesforce.php:909)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Brilliant Web-to-Lead for Salesforce Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[salesforce] salesforce.php:1156
WordPress Hooks 3
filtersfwp2l_validate_fieldexamples.php:193
actionwidgets_initsalesforce.php:31
actionplugins_loadedsalesforce.php:1270
Maintenance & Trust

Brilliant Web-to-Lead for Salesforce Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedFeb 24, 2022
PHP min version7.4
Downloads138K

Community Trust

Rating88/100
Number of ratings38
Active installs2K
Developer Profile

Brilliant Web-to-Lead for Salesforce Developer Profile

Nick Ciske

4 plugins · 2K total installs

80
trust score
Avg Security Score
80/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Brilliant Web-to-Lead for Salesforce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/salesforce-wordpress-to-lead/assets/css/sfwp2l.css/wp-content/plugins/salesforce-wordpress-to-lead/assets/js/jquery-placeholder/jquery.placeholder.js
Script Paths
/wp-content/plugins/salesforce-wordpress-to-lead/assets/js/jquery-placeholder/jquery.placeholder.js

HTML / DOM Fingerprints

CSS Classes
w2lleadwpcf7-formtop-alignedleft-alignedright-alignedbottom-aligned
HTML Comments
<!-- TODO: wrap in a class -->
Data Attributes
data-sfw2l-success-msgdata-sfw2l-error-msgdata-sfw2l-email-error-msgdata-sfw2l-captcha-error-msgdata-sfw2l-required-fields-textdata-sfw2l-sf-error-msg+20 more
JS Globals
sfwp2l
FAQ

Frequently Asked Questions about Brilliant Web-to-Lead for Salesforce