Impact
The vulnerability is a missing authorization flaw in the Zoho CRM Lead Magnet plugin for WordPress that allows users with insufficient privileges to exploit incorrectly configured access control mechanisms. Because the plugin does not enforce proper authentication checks on its endpoints, an attacker can request protected functionality or data that should be restricted, leading to unauthorized disclosure or manipulation of CRM information. This weakness is classified as CWE‑862: Missing Authorization.
Affected Systems
The issue affects the Zoho CRM Lead Magnet plugin for WordPress (cve vendor zohocrm:Zoho CRM Lead Magnet) from early versions up to and including 1.8.1.9. Any deployment of the plugin that has not been upgraded beyond version 1.8.1.9 is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is remote; an unauthenticated or low‑privileged user can send crafted HTTP requests to the plugin’s endpoints and gain access to protected functions. Determining whether the target site has an exposed endpoint depends on the plugin’s configuration, but the absence of authorization checks means that any user who can reach the plugin URL could exploit the flaw.
OpenCVE Enrichment