VYPR

Leadconnector

by WordPress

Source repositories

CVEs (3)

  • CVE-2024-34378HigMay 6, 2024
    risk 0.56cvss 8.6epss 0.00

    Missing Authorization vulnerability in LeadConnector.This issue affects LeadConnector: from n/a through 1.7.

  • CVE-2025-30893MedMar 27, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LeadConnector LeadConnector leadconnector allows DOM-Based XSS.This issue affects LeadConnector: from n/a through <= 3.0.2.

  • CVE-2024-1371MedApr 30, 2024
    risk 0.42cvss 6.5epss 0.00

    The LeadConnector plugin for WordPress is vulnerable to unauthorized modification & loss of data due to a missing capability check on the lc_public_api_proxy() function in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to delete arbitrary posts. CVE-2024-34378 is likely a duplicate of this issue.