LeadConnector Security & Risk Analysis

wordpress.org/plugins/leadconnector

LeadConnector: It helps you to add the LeadConnector chat widget and the LeadConnector funnel pages to your WordPress website.

30K active installs v3.0.26 PHP 5.6+ WP 5.0+ Updated Mar 31, 2026
chat-widgetcrmfunnellead-connectorleadconnector
95
A · Safe
CVEs total4
Unpatched0
Last CVEMar 30, 2026
Safety Verdict

Is LeadConnector Safe to Use in 2026?

Generally Safe

Score 95/100

LeadConnector has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

4 known CVEsLast CVE: Mar 30, 2026Updated 1mo ago
Risk Assessment

The 'leadconnector' plugin v3.0.24 exhibits a mixed security posture. On the positive side, static analysis indicates a strong adherence to secure coding practices regarding SQL queries and output escaping, with high percentages of prepared statements and properly escaped outputs. Furthermore, all identified entry points (AJAX, REST API, shortcodes, cron) appear to have authorization checks, which is a significant strength. The absence of critical or high severity taint flows is also reassuring.

However, several areas raise concerns. The presence of two known medium severity vulnerabilities in its history, specifically Cross-site Scripting and Missing Authorization, even though currently patched, indicates a pattern of past security weaknesses. The absence of nonce checks across all entry points is a notable oversight, potentially leaving the plugin vulnerable to CSRF attacks if authorization checks were ever bypassed or if specific actions were not properly protected. The taint analysis also flagged one flow with unsanitized paths, which warrants further investigation despite not being classified as critical or high severity in this analysis.

In conclusion, while the plugin demonstrates good practices in several key areas like SQL and output handling, the past vulnerability history and the lack of nonce checks present areas that require attention. The plugin's overall security is reasonably robust due to the current patching of known issues and the presence of authorization checks, but it is not without its risks.

Key Concerns

  • Missing nonce checks on entry points
  • Flows with unsanitized paths found
  • Two medium severity CVEs in history
Vulnerabilities
4 published

LeadConnector Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025
2025
2 CVEs in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
4

4 total CVEs

CVE-2026-1890medium · 5.3Missing Authorization

LeadConnector < 3.0.22 - Missing Authorization

Mar 30, 2026 Patched in 3.0.22 (11d)
CVE-2026-25441medium · 5.3Missing Authorization

LeadConnector <= 3.0.21 - Missing Authorization

Jan 23, 2026 Patched in 3.0.22 (102d)
CVE-2025-30893medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

LeadConnector <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 27, 2025 Patched in 3.0.3 (7d)
CVE-2024-1371medium · 6.5Missing Authorization

LeadConnector <= 1.7 - Missing Authorization to Unauthenticated Arbitrary Post Deletion

Apr 29, 2024 Patched in 1.8 (9d)
Version History

LeadConnector Release Timeline

Code Analysis
Analyzed Mar 16, 2026

LeadConnector Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
8 prepared
Unescaped Output
15
69 escaped
Nonce Checks
0
Capability Checks
6
File Operations
2
External Requests
10
Bundled Libraries
0

SQL Query Safety

89% prepared9 total queries

Output Escaping

82% escaped84 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<seo-overrides> (includes\SeoOverrides\seo-overrides.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

LeadConnector Attack Surface

Entry Points9
Unprotected0

REST API Routes 3

GET/wp-json/lc_public_api/v1/proxyadmin\class-lc-admin.php:1878
GET/wp-json/lc_public_api/v1proxyadmin\class-lc-admin.php:1887
GET/wp-json/lc_internal_api/v1/save_custom_valuesadmin\class-lc-admin.php:1900

Shortcodes 6

[lc_phone_number_pool] includes\class-lc-loader.php:192
[lc_form] includes\class-lc-loader.php:211
[lc_calendar] includes\class-lc-loader.php:248
[lc_survey] includes\class-lc-loader.php:263
[lc_quiz] includes\class-lc-loader.php:278
[lc_reviews_widget] includes\class-lc-loader.php:306
WordPress Hooks 63
actionadmin_noticesadmin\class-lc-admin.php:65
actionadmin_headadmin\class-lc-admin.php:66
actionwp_enqueue_scriptsadmin\class-lc-admin.php:69
filterauto_update_coreadmin\class-lc-admin.php:1096
filterauto_update_pluginadmin\class-lc-admin.php:1099
filterauto_update_themeadmin\class-lc-admin.php:1102
filterauto_update_translationadmin\class-lc-admin.php:1105
filterautomatic_updater_disabledadmin\class-lc-admin.php:1108
filterscript_loader_tagadmin\class-lc-admin.php:1823
filterthe_contentadmin\class-lc-admin.php:2390
actionwp_headadmin\class-lc-admin.php:2441
actionwp_footeradmin\class-lc-admin.php:2593
filterbody_classadmin\class-lc-admin.php:2606
actionadmin_noticesadmin\class-lc-admin.php:2919
actioninitincludes\class-lc-i18n.php:37
filterphpmailer_initincludes\class-lc-loader.php:175
actioninitincludes\class-lc-loader.php:318
actionlc_twicedaily_refresh_req_v2includes\class-lc-loader.php:332
actionplugins_loadedincludes\class-lc.php:149
actionadmin_enqueue_scriptsincludes\class-lc.php:165
actionadmin_enqueue_scriptsincludes\class-lc.php:166
actionwp_enqueue_scriptsincludes\class-lc.php:167
actioninitincludes\class-lc.php:169
actionrest_api_initincludes\class-lc.php:171
actioninitincludes\class-lc.php:172
actionadmin_menuincludes\class-lc.php:174
actionadmin_initincludes\class-lc.php:175
actiontemplate_redirectincludes\class-lc.php:176
actionsave_postincludes\class-lc.php:178
actionwp_enqueue_scriptsincludes\class-lc.php:193
actionwp_enqueue_scriptsincludes\class-lc.php:194
actionadmin_menuincludes\lc-menu-handler.php:142
actionadmin_menuincludes\lc-menu-handler.php:173
actionplugins_loadedincludes\lc-update-functions.php:83
filterdocument_title_partsincludes\SeoOverrides\seo-overrides.php:66
actionwp_headincludes\SeoOverrides\seo-overrides.php:75
filterquery_varsLeadConnector.php:69
actionwp_enqueue_scriptsLeadConnector.php:175
actionwp_enqueue_scriptsLeadConnector.php:192
filterbody_classpublic\class-lc-funnel-template-handler.php:100
actionwp_headpublic\class-lc-funnel-template-handler.php:106
actionwp_footerpublic\class-lc-funnel-template-handler.php:178
filterthe_contentpublic\class-lc-public.php:106
filterthe_excerptpublic\class-lc-public.php:107
filterthe_titlepublic\class-lc-public.php:110
filterwp_titlepublic\class-lc-public.php:111
filterdocument_title_partspublic\class-lc-public.php:112
filterpre_get_document_titlepublic\class-lc-public.php:113
filterwidget_textpublic\class-lc-public.php:116
filterwidget_text_contentpublic\class-lc-public.php:117
filterwidget_titlepublic\class-lc-public.php:118
filterget_the_excerptpublic\class-lc-public.php:121
filtermeta_descriptionpublic\class-lc-public.php:122
filternav_menu_item_titlepublic\class-lc-public.php:126
filterwp_nav_menu_itemspublic\class-lc-public.php:127
filterrender_block_core/navigationpublic\class-lc-public.php:130
filterrender_block_core/navigation-linkpublic\class-lc-public.php:131
filterrender_block_core/page-listpublic\class-lc-public.php:132
filterrender_blockpublic\class-lc-public.php:133
filtercomment_textpublic\class-lc-public.php:136
filtercomment_excerptpublic\class-lc-public.php:137
actionwp_headpublic\class-lc-public.php:140
actionwp_headpublic\class-lc-public.php:357

Scheduled Events 1

lc_twicedaily_refresh_req_v2
Maintenance & Trust

LeadConnector Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 31, 2026
PHP min version5.6
Downloads729K

Community Trust

Rating72/100
Number of ratings23
Active installs30K
Developer Profile

LeadConnector Developer Profile

LeadConnector

1 plugin · 30K total installs

85
trust score
Avg Security Score
95/100
Avg Patch Time
32 days
View full developer profile
Detection Fingerprints

How We Detect LeadConnector

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/leadconnector/assets/css/custom-elementor.css/wp-content/plugins/leadconnector/assets/css/theme-fixes.css
Version Parameters
leadconnector/assets/css/custom-elementor.css?ver=leadconnector/assets/css/theme-fixes.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-lc-settings
JS Globals
leadconnector
FAQ

Frequently Asked Questions about LeadConnector