Description
WordPress Plugin LeadConnector is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently delete arbitrary posts or pages. WordPress Plugin LeadConnector version 1.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.8 or latest
References
Related Vulnerabilities
Mailman Other Vulnerability (CVE-2002-0388)
MySQL Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2016-6664)
ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-4390)
WordPress Plugin Toggle The Title Cross-Site Scripting (1.4)