Description
WordPress Plugin LeadConnector is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently delete arbitrary posts or pages. WordPress Plugin LeadConnector version 1.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.8 or latest
References
Related Vulnerabilities
MySQL CVE-2021-35648 Vulnerability (CVE-2021-35648)
ProjectSend Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-53980)
WordPress Plugin Request For Quote Cross-Site Request Forgery (1.2)
WordPress Plugin Contact Form by Supsystic Cross-Site Scripting (1.7.14)
Jenkins Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2018-1999044)