
Brilliant Web-to-Lead for Salesforce Security & Risk Analysis
wordpress.org/plugins/salesforce-wordpress-to-leadBrilliant Web-to-Lead for Salesforce creates a solid integration between your WordPress install(s) and your Salesforce.com account!
Is Brilliant Web-to-Lead for Salesforce Safe to Use in 2026?
Use With Caution
Score 63/100Brilliant Web-to-Lead for Salesforce has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The Salesforce WordPress to Lead plugin, version 2.7.3.9, exhibits a mixed security posture. While the static analysis highlights some good practices, such as 100% of SQL queries using prepared statements and a high percentage of properly escaped output, significant concerns remain. The lack of any nonce checks or capability checks for its single shortcode is a notable weakness, as this represents a potential entry point without proper authorization or validation. Furthermore, the plugin has a history of vulnerabilities, with one unpatched medium severity CVE and a past incident involving Cross-Site Request Forgery (CSRF). The presence of two external HTTP requests also warrants scrutiny, as these could be exploited if not handled securely.
The taint analysis reveals two flows with unsanitized paths, which, while not classified as critical or high severity in this analysis, indicate potential areas where user-supplied data could be processed insecurely. The vulnerability history, particularly the ongoing unpatched medium CVE and the past CSRF issue, suggests a recurring pattern of security oversights. Although there are strengths in its query and output handling, the identified lack of checks on its shortcode and the unaddressed historical vulnerabilities present tangible risks that users should be aware of.
Key Concerns
- Unpatched medium severity CVE
- Shortcode lacks nonce and capability checks
- Flows with unsanitized paths
- External HTTP requests
Brilliant Web-to-Lead for Salesforce Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
To Lead For Salesforce <= 2.7.3.9 - Cross-Site Request Forgery
Brilliant Web-to-Lead for Salesforce Code Analysis
Output Escaping
Data Flow Analysis
Brilliant Web-to-Lead for Salesforce Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Brilliant Web-to-Lead for Salesforce Maintenance & Trust
Maintenance Signals
Community Trust
Brilliant Web-to-Lead for Salesforce Alternatives
Zoho CRM Lead Magnet
zoho-crm-forms
Websites are one of the most important sources of leads for your business.
ACF Field For CF7
acf-field-for-contact-form-7
Adds a 'Contact Form 7' field type for the Advanced Custom Fields WordPress plugin.
AFI – The Easiest Integration Plugin
advanced-form-integration
Connect any WordPress form or event to 200+ apps — no code. Send leads, orders, and signups to your CRM, email, or sheets in minutes.
Lenix Leads Collector
lenix-elementor-leads-addon
Leads Collector, Collects forms entries from Elementor,Cf7,WPForms and more with export to CSV.
Contact Form to Any API
contact-form-to-any-api
Send Contact Form 7 submissions to any API, Webhook or CRM - quick setup, flexible payloads, endpoints and authentication.
Brilliant Web-to-Lead for Salesforce Developer Profile
4 plugins · 2K total installs
How We Detect Brilliant Web-to-Lead for Salesforce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/salesforce-wordpress-to-lead/assets/css/sfwp2l.css/wp-content/plugins/salesforce-wordpress-to-lead/assets/js/jquery-placeholder/jquery.placeholder.js/wp-content/plugins/salesforce-wordpress-to-lead/assets/js/jquery-placeholder/jquery.placeholder.jsHTML / DOM Fingerprints
w2lleadwpcf7-formtop-alignedleft-alignedright-alignedbottom-aligned<!-- TODO: wrap in a class -->data-sfw2l-success-msgdata-sfw2l-error-msgdata-sfw2l-email-error-msgdata-sfw2l-captcha-error-msgdata-sfw2l-required-fields-textdata-sfw2l-sf-error-msg+20 moresfwp2l