PT-2025-40614 · WordPress · Integrate Dynamics 365 Crm Plugin For Wordpress

Jonas Benjamin Friedli

·

Published

2025-10-04

·

Updated

2025-10-04

·

CVE-2025-10746

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Integrate Dynamics 365 CRM plugin for WordPress versions through 1.0.9
Description The Integrate Dynamics 365 CRM plugin for WordPress is susceptible to unauthorized access due to missing capability checks and nonce verification on functions hooked to 'init'. This allows unauthenticated attackers to deactivate the plugin, modify OAuth configuration, and initiate test connections that reveal sensitive data through direct requests to vulnerable API endpoints by crafting malicious requests with specific parameters.
Recommendations Update Integrate Dynamics 365 CRM plugin for WordPress to a version later than 1.0.9.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-10746

Affected Products

Integrate Dynamics 365 Crm Plugin For Wordpress