Description
Missing Authorization vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP-CRM System: from n/a through <= 3.4.2.
Published: 2025-06-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing Authorization in the WP-CRM System plugin allows a user to invoke operations that are not properly constrained by access control lists. This flaw enables an attacker who can reach the plugin’s functions to perform actions intended only for privileged users, potentially exposing sensitive customer data or manipulating the CRM. The weakness is a classic example of improper authorization (CWE‑862).

Affected Systems

The vulnerability affects the WordPress WP‑CRM System plugin developed by Mario Peshev. All released versions from the earliest available through version 3.4.2 are impacted. Users running the plugin on any WordPress installation should assume the plugin is vulnerable until updated to a later version that fixes the authorization check.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% shows the likelihood of public exploitation is very low, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw allows privileged actions to be performed by any authenticated or potentially unauthenticated user, an attacker could exploit it with minimal effort if the plugin is publicly accessible. The likely attack vector is remote, via the web interface, and would require the attacker to convince a user to visit a crafted URL or send a direct HTTP request to the plugin’s endpoints. Official mitigation is to apply a patch; no workaround is documented. Given the low exploitation probability, monitoring is recommended until a patch is confirmed, but administrators should update immediately to eliminate the authority bypass.

Generated by OpenCVE AI on April 30, 2026 at 18:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update WP‑CRM System plugin to version 3.4.3 or later, which includes the authorization fixes.
  • Apply temporary access restrictions to the plugin’s admin area, such as disabling the plugin or limiting its functionality to administrators only, until the update is applied.
  • Enable detailed logging for the plugin’s operations and monitor logs for unusual or unauthorized activity related to WP‑CRM System functions.

Generated by OpenCVE AI on April 30, 2026 at 18:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17281 Missing Authorization vulnerability in Mario Peshev WP-CRM System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WP-CRM System: from n/a through 3.4.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Mario Peshev WP-CRM System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WP-CRM System: from n/a through 3.4.2. Missing Authorization vulnerability in Mario Peshev WP-CRM System wp-crm-system allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP-CRM System: from n/a through <= 3.4.2.
Title WordPress WP-CRM System <= 3.4.2 - Broken Access Control Vulnerability WordPress WP-CRM System plugin <= 3.4.2 - Broken Access Control Vulnerability
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Fri, 06 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 13:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Mario Peshev WP-CRM System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WP-CRM System: from n/a through 3.4.2.
Title WordPress WP-CRM System <= 3.4.2 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:59.516Z

Reserved: 2025-06-04T09:41:22.715Z

Link: CVE-2025-49270

cve-icon Vulnrichment

Updated: 2025-06-06T19:01:11.582Z

cve-icon NVD

Status : Deferred

Published: 2025-06-06T13:15:43.353

Modified: 2026-04-23T15:31:21.773

Link: CVE-2025-49270

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T18:45:21Z

Weaknesses