Description
WordPress Plugin LeadConnector is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently delete arbitrary posts or pages. WordPress Plugin LeadConnector version 1.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.8 or latest
References
Related Vulnerabilities
MediaWiki Incorrect Authorization Vulnerability (CVE-2023-22945)
e107 Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2008-1989)
WordPress 4.5.x Multiple Vulnerabilities (4.5 - 4.5.17)
WordPress Plugin PI Button includes Backdoor [Only if downloaded via the vendor website] (3.3.3)