PT-2026-2818 · WordPress · Wp-Crm System+1

Teerachai Somprasong

·

Publicado

2026-01-14

·

Atualizado

2026-01-14

·

CVE-2025-14854

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP-CRM System plugin for WordPress versions up to and including 3.4.5
Description The WP-CRM System plugin for WordPress is susceptible to unauthorized access because of absent capability checks within the wpcrm get email recipients and wpcrm system ajax task change status AJAX functions. This allows authenticated attackers possessing subscriber-level access or higher to enumerate CRM contact email addresses, resulting in potential PII disclosure, and to modify CRM task statuses.
Recommendations Update the WP-CRM System plugin to a version later than 3.4.5.

Correção

LPE

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-14854

Produtos afetados

Wp-Crm System
Wordpress