CVE-2026-1890 Scanner
CVE-2026-1890 Scanner - Unauthenticated Arbitrary Data Write vulnerability in LeadConnector WordPress Plugin
Short Info
Level
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
10 seconds
Time Interval
22 days 17 hours
Scan only one
Domain, Subdomain, IPv4
Toolbox
LeadConnector is a WordPress plugin widely used by digital marketers, businesses, and agencies for managing customer data and optimizing lead generation. It allows users to track interactions and automate marketing campaigns efficiently. The plugin integrates seamlessly with various CRM systems, enhancing its versatility. Users rely on LeadConnector to improve their marketing workflows, ensuring better conversion rates. Given its critical role in managing sensitive data, it is imperative that the plugin maintains robust security measures. The vulnerability discovered affects its REST API, potentially compromising site data integrity.
This vulnerability in the LeadConnector plugin allows unauthenticated attackers to write arbitrary data remotely. This could be exploited by sending crafted requests to a vulnerable REST endpoint. The lack of proper authorization checks within the plugin makes exploitation relatively straightforward. Attackers don't need any credentials to execute this, thereby increasing its risk profile. Such vulnerabilities can undermine the confidence in site security, leading to data manipulation. Patching this vulnerability is crucial to maintaining the integrity of data managed through the plugin.
The vulnerable endpoint in LeadConnector is within its REST API. Attackers can exploit the '/wp-json/lc_internal_api/v1/save_custom_values' endpoint. By crafting specific POST requests, attackers can save custom data values. The plugin doesn't implement adequate checks, allowing data overwrite. An exploit is successful when unauthorized data writing occurs, confirmed through JSON responses. Site administrators are urged to update immediately to secure versions.
Exploitation of this vulnerability can lead to unauthorized data changes, potentially causing irreversible data loss. Data integrity might be compromised, affecting the accuracy of customer data. It could result in significant disruptions to marketing campaigns dependent on precise data. Businesses could incur financial losses due to data inconsistencies and damaged reputations from poor security posture. Immediate action is necessary to prevent these damaging effects and protect digital assets.
REFERENCES