SALESmanago & Leadoo
by WordPress
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-10835 | Hig | 0.00 | 7.7 | 0.00 | Jun 26, 2026 | The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one of its AJAX actions before using it in a SQL statement, and fails to enforce authorisation on that action, allowing authenticated users with minimal… | ||
| CVE-2026-54822 | Hig | 0.00 | 8.5 | 0.00 | Jun 25, 2026 | Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions. |
- risk 0.00cvss 7.7epss 0.00
The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one of its AJAX actions before using it in a SQL statement, and fails to enforce authorisation on that action, allowing authenticated users with minimal…
- risk 0.00cvss 8.5epss 0.00
Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.