The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated users to call it and overwrite existing data
Subscriptions
No data.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 26 Mar 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated users to call it and overwrite existing data | |
| Title | LeadConnector < 3.0.22 - Unauthenticated Rest Call | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-03-26T06:00:09.659Z
Reserved: 2026-02-04T14:26:21.828Z
Link: CVE-2026-1890
No data.
Status : Received
Published: 2026-03-26T07:16:19.907
Modified: 2026-03-26T07:16:19.907
Link: CVE-2026-1890
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.