Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2026-04-15

CVE-2026-1890 - Leadconnector Plugin

The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated users to call it and overwrite existing data

PLUGIN Leadconnector

CVE-2026-1890

MEDIUM CVSS 5.3 2026-03-26
Threat Entry Updated 2024-11-21

CVE-2024-1371 - Leadconnector Plugin

The LeadConnector plugin for WordPress is vulnerable to unauthorized modification & loss of data due to a missing capability check on the lc_public_api_proxy() function in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to delete arbitrary posts.

PLUGIN Leadconnector

CVE-2024-1371

MEDIUM CVSS 6.5 2024-04-30
Scroll to top