PT-2026-2818 · WordPress · Wp-Crm System+1

Teerachai Somprasong

·

Published

2026-01-14

·

Updated

2026-01-14

·

CVE-2025-14854

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP-CRM System plugin for WordPress versions up to and including 3.4.5
Description The WP-CRM System plugin for WordPress is susceptible to unauthorized access because of absent capability checks within the wpcrm get email recipients and wpcrm system ajax task change status AJAX functions. This allows authenticated attackers possessing subscriber-level access or higher to enumerate CRM contact email addresses, resulting in potential PII disclosure, and to modify CRM task statuses.
Recommendations Update the WP-CRM System plugin to a version later than 3.4.5.

Fix

LPE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-14854

Affected Products

Wp-Crm System
Wordpress