VYPR

Leadconnector

by WordPress

Source repositories

CVEs (5)

  • CVE-2024-34378HigMay 6, 2024
    risk 0.56cvss 8.6epss 0.00

    Missing Authorization vulnerability in LeadConnector.This issue affects LeadConnector: from n/a through 1.7.

  • CVE-2025-30893MedMar 27, 2025
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LeadConnector LeadConnector leadconnector allows DOM-Based XSS.This issue affects LeadConnector: from n/a through <= 3.0.2.

  • CVE-2024-1371MedApr 30, 2024
    risk 0.42cvss 6.5epss 0.01

    The LeadConnector plugin for WordPress is vulnerable to unauthorized modification & loss of data due to a missing capability check on the lc_public_api_proxy() function in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to delete…

  • CVE-2026-1890MedMar 26, 2026
    risk 0.35cvss 5.3epss 0.01

    The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated users to call it and overwrite existing data

  • CVE-2026-25441MedFeb 19, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in varunvairavanlc LeadConnector leadconnector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LeadConnector: from n/a through <= 3.0.21.