ZeroHour

CVE-2026-81298

moderate

Unauthenticated XSS in LeadConnector WordPress plugin (≤ 4.0.5)

CVSS 3.1
7.1 high
EPSS
<1%p8
Published
()
Modified
AI analysis

CVE-2026-81298 is an unauthenticated cross-site scripting (XSS) flaw in the LeadConnector WordPress plugin, affecting all versions up to and including 4.0.5. The plugin fails to properly sanitize user-controlled input that can be reached without logging in, so an attacker can craft input or a crafted URL/interaction that causes arbitrary JavaScript to execute in the browser of a victim who views the affected page. Because the CVSS scope is marked as changed, successful injection can cross security boundaries (e.g., a site visitor's or administrator's browser context), letting the attacker steal session data, perform actions as the victim, or alter page content. Any WordPress site running the LeadConnector plugin at version 4.0.5 or older is affected. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at roughly 0.2%, indicating no known exploitation in the wild.

What to do: Update the LeadConnector plugin to the latest available release, ensuring the installed version is newer than 4.0.5. Until patched, consider a web application firewall or WAF rule to block unsanitized parameters targeting the plugin, and review recent site activity or logs for signs of injected scripts. Note that a successful exploit only executes when a user loads the affected content, so no evidence of compromise means low risk, but patching should still be treated as high priority given the unauthenticated nature of the flaw.

Affected
GoHighLevel (LeadConnector plugin author) LeadConnector – WordPress plugin<= 4.0.5
Estimated exposure
moderateon the order of tens of thousands of WordPress sites (est.) — The LeadConnector plugin is the WordPress integration for the widely used GoHighLevel marketing platform and WordPress.org listings have shown it with active installs in the tens of thousands, though the exact unpatched and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.