The WP-CRM System plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on the wpcrm_get_email_recipients and wpcrm_system_ajax_task_change_status AJAX functions in all versions up to, and including, 3.4.5. This makes it possible for authenticated attackers, with subscriber level access and above, to enumerate CRM contact email addresses (PII disclosure) and modify CRM task statuses.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-14 06:15
Updated : 2026-01-14 16:25
NVD link : CVE-2025-14854
Mitre link : CVE-2025-14854
CVE.ORG link : CVE-2025-14854
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
