CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.3. It affects WordPress. Exploitation may require the attacker to be authenticated.
CVE
CVE-2026-1890
Severity
MEDIUM
CVSS
5.3
EPSS
0.68%
WordPress
Original NVD Description
The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated users to call it and overwrite existing data