cleantalk
Vulnerabilities and Security Researches

LeadConnector, CVE-2026-1890

CVE, Research URL

CVE-2026-1890

Application

LeadConnector

Published on
Mar 26, 2026
Research Description
The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated users to call it and overwrite existing data
Affected versions
max 3.0.22.
Status
vulnerable