CVE-2026-81298
moderateUnauthenticated XSS in LeadConnector WordPress plugin (≤ 4.0.5)
CVE-2026-81298 is an unauthenticated cross-site scripting (XSS) flaw in the LeadConnector WordPress plugin, affecting all versions up to and including 4.0.5. The plugin fails to properly sanitize user-controlled input that can be reached without logging in, so an attacker can craft input or a crafted URL/interaction that causes arbitrary JavaScript to execute in the browser of a victim who views the affected page. Because the CVSS scope is marked as changed, successful injection can cross security boundaries (e.g., a site visitor's or administrator's browser context), letting the attacker steal session data, perform actions as the victim, or alter page content. Any WordPress site running the LeadConnector plugin at version 4.0.5 or older is affected. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at roughly 0.2%, indicating no known exploitation in the wild.
What to do: Update the LeadConnector plugin to the latest available release, ensuring the installed version is newer than 4.0.5. Until patched, consider a web application firewall or WAF rule to block unsanitized parameters targeting the plugin, and review recent site activity or logs for signs of injected scripts. Note that a successful exploit only executes when a user loads the affected content, so no evidence of compromise means low risk, but patching should still be treated as high priority given the unauthenticated nature of the flaw.
| GoHighLevel (LeadConnector plugin author) LeadConnector – WordPress plugin | <= 4.0.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.