CVE•Published 2026-03-26•1 article on news•5 live references•NVD data

CVE-2026-1890

Vulnerability data via CVEDB (Shodan)

CVSS v3.1
5.3
MEDIUM
EPSS percentile
51
Exploit Prediction Scoring System · top 49% of all CVEs
Description

The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated users to call it and overwrite existing data

Timeline
Published 2026-03-26

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub (3)