🔐 CVE Alert

CVE-2026-1890

MEDIUM 5.3

LeadConnector < 3.0.22 - Unauthenticated Rest Call

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
6th

The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated users to call it and overwrite existing data

Vendor unknown
Product leadconnector
Published Mar 26, 2026
Last Updated Mar 26, 2026
Stay Ahead of the Next One

Get instant alerts for unknown leadconnector

Be the first to know when new medium vulnerabilities affecting unknown leadconnector are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / LeadConnector
0 < 3.0.22

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/9b88be70-b5cc-4a3f-a871-64d61cb02076/

Credits

yiğit ibrahim sağlam WPScan