Impact
The vulnerability is an unauthenticated cross‑site scripting flaw present in all releases of the WordPress LeadConnector plugin up to version 4.0.5. It allows the injection of arbitrary JavaScript into web pages rendered by the plugin. Based on the description, it is inferred that attackers could execute malicious scripts in visitors' browsers, potentially compromising their session or defacing content.
Affected Systems
Products affected are the LeadConnector plugin developed by varunvairavanlc. Vulnerable releases include all versions up to and including 4.0.5. Any WordPress installation using those versions without applying the patch to version 4.0.6 or later remains at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog, implying no known active exploitation. Because the flaw is unauthenticated, an attacker can exploit it from any network location that can reach the WordPress site. The attack path requires the attacker to craft a request that injects malicious JavaScript into a page hosted by the plugin, which then runs in the context of any user who views the page.
OpenCVE Enrichment