CVE-2026-1890
MEDIUM EXPLOITED NUCLEILeadConnector < 3.0.22 - Unauthenticated Rest Call
Title source: cnaExploitation Summary
CVE-2026-1890 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.
Description
The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated users to call it and overwrite existing data
Nuclei Templates (1)
LeadConnector < 3.0.22 - Unauthenticated Arbitrary Data Write
MEDIUMVERIFIEDby 0x_Akoko
Shodan:
http.html:"leadconnector"
FOFA:
body="/wp-content/plugins/leadconnector/"
References (1)
Core 1
Core References
Exploit exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/9b88be70-b5cc-4a3f-a871-64d61cb02076/
Scores
CVSS v3
5.3
EPSS
0.0068
EPSS Percentile
48.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
VulnCheck KEV
2026-04-30
Status
published
Products (1)
Unknown/LeadConnector
< 3.0.22
Published
Mar 26, 2026
Tracked Since
Mar 26, 2026