LeadConnector
LeadConnector has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 5 are fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high. 2026 was the busiest year with 3 disclosures.
The most common weakness is Missing Authorization, behind 3 of the records (60%). Other recurring categories include Cross-Site Scripting.
Every one of the 5 issues recorded for LeadConnector has a vendor fix available, so running the current release closes all known holes.
5 independent researchers contributed these findings, one record each. LeadConnector is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2026-81298LeadConnector <= 4.0.5 - Unauthenticated Stored Cross-Site Scripting
Read the full analysisVulnerability Records

LeadConnector
Author
LeadConnector
Turn your WordPress site into a LeadConnector-powered conversion engine. LeadConnector connects WordPress with your LeadConnector CRM so your site can capture leads, book appointments, publish funnels, display reviews, and personalize content from one connected admin experience. Key Features Lead capture tools: Add chat widgets, forms, surveys, quizzes, calendars, phone pools, and reviews widgets. Funnel publishing: Import LeadConnector funnel steps as WordPress pages using iframe, redirect, or native HTML display. CRM personalization: Sync LeadConnector custom values into WordPress content. Email and SEO: Send WordPress email through LeadConnector SMTP and manage page metadata. AI and cache tools: Use supported AI Pages workflows and purge Rocket.net cache when configured.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C