Executive brief
LeadConnector is a WordPress plugin for customer relationship management and lead capture. The plugin contains a cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to inject malicious scripts into affected websites. Exploited scripts can steal visitor data, hijack user accounts, or redirect users to phishing pages, affecting both site operators and their visitors.
Technical details
The vulnerability is an unauthenticated cross-site scripting (XSS) flaw in LeadConnector versions up to 4.0.5. The vulnerability requires user interaction—such as clicking a malicious link or visiting a crafted page—for successful exploitation. An attacker can craft a malicious URL or page that injects JavaScript into the website context, potentially stealing session cookies, credentials, or sensitive customer data. The vendor released patched version 4.0.6 on or before 28 August 2026; affected sites should update immediately.
Affected products
- LeadConnector LeadConnector <=4.0.5
Timeline
- 2026-08-31: disclosed: Published on NVD
- 2026-08-28: patched: Version 4.0.6 released as patched version