Unauthenticated Cross Site Scripting in LeadConnector by WordPress
CVE-2026-81298
7.1HIGH
What is CVE-2026-81298?
An unauthenticated cross site scripting vulnerability has been identified in the LeadConnector plugin for WordPress versions up to 4.0.5. This allows attackers to inject arbitrary scripts into web pages, potentially compromising user data and sessions. It effectively enables unauthorized users to execute malicious code within the context of a user's browser, which can lead to further exploits within the WordPress environment.
Affected Version(s)
LeadConnector <= 4.0.5