VYPR

SALESmanago & Leadoo

by WordPress

CVEs (2)

  • CVE-2026-10835Jun 26, 2026
    risk 0.00cvss epss 0.00

    The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one of its AJAX actions before using it in a SQL statement, and fails to enforce authorisation on that action, allowing authenticated users with minimal…

  • CVE-2026-54822Jun 25, 2026
    risk 0.00cvss epss 0.00

    Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.