Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
Threat Entry
Updated 2026-04-15
CVE-2026-1890 - Leadconnector Plugin
The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated users to call it and overwrite existing data
PLUGIN
Leadconnector
CVE-2026-1890
Risk Score
Threat Entry
Updated 2024-11-21
CVE-2024-1371 - Leadconnector Plugin
The LeadConnector plugin for WordPress is vulnerable to unauthorized modification & loss of data due to a missing capability check on the lc_public_api_proxy() function in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to delete arbitrary posts.
PLUGIN
Leadconnector
CVE-2024-1371
Risk Score
