CVE-2026-81298: WordPress LeadConnector plugin <= 4.0.5 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress LeadConnector pluginto a version that resolves this vulnerability.Fixed in 4.0.6
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or existing plugin privileges. Exploitation still requires user interaction, as indicated by the UI:R attack vector.
Which installations are affected?
LeadConnector versions 4.0.5 and earlier are affected. The provided information does not identify a fixed version or any configuration conditions that would limit exposure.
What impact could successful exploitation have?
Successful XSS may allow an attacker to affect confidentiality, integrity, and availability at low impact levels. The scope is changed, meaning the impact can extend beyond the vulnerable plugin's own security authority.