plugin

Leadconnector Vulnerabilities

5 known security issues reported for the Leadconnector WordPress plugin. Most recent disclosed Mar 30, 2026.

5 medium

Running Leadconnector on your site? Check whether your installed version is affected.

Scan your site free

LeadConnector - Unauthenticated Rest Call vulnerability

medium

Unauthenticated Rest Call vulnerability

CVSS:
6.5
Affected:
up to 3.0.22
Fixed in:
3.0.22
Disclosed:
Mar 30, 2026

LeadConnector < 3.0.22 - Missing Authorization

medium

The LeadConnector plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 3.0.22 (exclusive). This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.0.22
Fixed in:
3.0.22
Disclosed:
Mar 30, 2026

CVE-2026-1890 on NVD →

LeadConnector <= 3.0.21 - Missing Authorization

medium

The LeadConnector plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.0.21. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.0.21
Fixed in:
3.0.22
Disclosed:
Jan 23, 2026

CVE-2026-25441 on NVD →

LeadConnector <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The LeadConnector plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages th...

CVSS:
6.4
Affected:
up to 3.0.2
Fixed in:
3.0.3
Disclosed:
Mar 27, 2025

CVE-2025-30893 on NVD →

LeadConnector <= 1.7 - Missing Authorization to Unauthenticated Arbitrary Post Deletion

medium

The LeadConnector plugin for WordPress is vulnerable to unauthorized modification & loss of data due to a missing capability check on the lc_public_api_proxy() function in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to delete arbitrary posts. CVE-2024-34378 is likely a d...

CVSS:
6.5
Affected:
up to 1.7
Fixed in:
1.8
Disclosed:
Apr 29, 2024

CVE-2024-1371 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database