Impact
The CRM Memberships plugin contains a missing capability check in the 'ntzcrm_add_new_tag' AJAX handler. An attacker can invoke this action without authentication and create arbitrary membership tags or modify configuration settings that should be reserved for administrators. This permits unauthorized manipulation of the marketing/CRM system and potential leakage of sensitive data.
Affected Systems
WordPress plugin CRM Memberships from vendor dripadmin, versions up to and including 2.5 are affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the attack vector is a web‑based AJAX request that can be performed from any location without credentials, making the issue easy to exploit for a determined adversary.
OpenCVE Enrichment