PT-2025-49191 · WordPress · Crm Memberships

Athiwat Tiprasaharn

·

Published

2025-12-05

·

Updated

2025-12-05

·

CVE-2025-13312

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions CRM Memberships plugin for WordPress versions prior to 2.6
Description The CRM Memberships plugin for WordPress is susceptible to unauthorized membership tag creation. This is due to a missing capability check within the ntzcrm add new tag() function. This allows unauthenticated attackers to create arbitrary membership tags and modify CRM configuration intended for administrators only.
Recommendations Update the CRM Memberships plugin to version 2.6 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-13312

Affected Products

Crm Memberships