CVE-2025-30893

WordPress LeadConnector plugin <= 3.0.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LeadConnector LeadConnector allows DOM-Based XSS. This issue affects LeadConnector: from n/a through 3.0.2.


We have discovered 955 live websites that are affected by CVE-2025-30893.

Run a Free Instant Scan




Affected Software

Product  LeadConnector
Category Wordpress Plugins
Vulnerable Domains955 live websites (12% of LeadConnector install base)
Vulnerable Versions
  • from 0 through 3.0.2
Vulnerable Versions Count6 versions ( 21% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Mar 27, 2025
  • Updated - Mar 27, 2025

Credits

  • Peter Thaleikis (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2025-30893
United States635 websites



GB71 websites
Australia50 websites
Canada37 websites
Germany17 websites
Bulgaria15 websites
Cyprus11 websites
France10 websites
Italy8 websites

Website Distribution by TLD

Number of websites using CVE-2025-30893
.com682 websites
.co.uk49 websites
.com.au44 websites
.ca23 websites
.org16 websites
.net16 websites
.co8 websites
.it6 websites
.dk5 websites
.de5 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-30893

Top websites that are affected by CVE-2025-30893. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****************.com United Arab Emirates***,***
***************.com United States***,***
*****************.com GB***,***
******************.com United States***,***
************.com United States***,***
********************.com United States*,***,***
**************.com United States*,***,***
********************.com United States*,***,***
****.ie Ireland*,***,***
******.com United States*,***,***
See full domain list

FAQ

CVE-2025-30893 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in LeadConnector
A total of 955 websites have been identified as vulnerable to CVE-2025-30893, based on global website indexing conducted by WebTechSurvey.
The LeadConnector is affected by the CVE-2025-30893 vulnerability.
LeadConnector versions up to and including 3.0.2 are vulnerable to CVE-2025-30893.