Impact
The Devs CRM – Manage tasks, attendance and teams all together plugin for WordPress contains a missing capability check on the /wp-json/devs-crm/v1/bulk-update REST‑API endpoint in all versions up to and including 1.1.8. This absence of authorization allows unauthenticated attackers to modify lead tags in bulk, thereby changing data stored in the CRM. The vulnerability does not grant code execution or direct access to the server, but it compromises data integrity by enabling unauthorized modification of lead information.
Affected Systems
All installations of the Devs CRM – Manage tasks, attendance and teams all together WordPress plugin with a version of 1.1.8 or earlier are affected. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of < 1% reflects a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this flaw by sending unauthenticated HTTP requests to the /wp-json/devs-crm/v1/bulk-update endpoint, resulting in unauthorized changes to lead tags. No additional credentials or privileged access are required, making the exploitation path straightforward for attackers.
OpenCVE Enrichment