CVE-2026-1890
LeadConnector < 3.0.22 - Unauthenticated Rest Call
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
6th
The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated users to call it and overwrite existing data
| Vendor | unknown |
| Product | leadconnector |
| Published | Mar 26, 2026 |
| Last Updated | Mar 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown leadconnector
Be the first to know when new medium vulnerabilities affecting unknown leadconnector are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / LeadConnector
0 < 3.0.22
References
Credits
yiğit ibrahim sağlam WPScan