Impact
FluentCRM Pro versions up to 3.1.12 allow an authenticated editor to gain higher privileges by exploiting an improper privilege check within the plugin. This flaw can be leveraged to create or assign additional roles with the same level of access, effectively elevating the attacker’s capabilities while remaining within the WordPress environment. The vulnerability corresponds to CWE‑266, representing improper privilege management. Affected systems include the WordPress FluentCRM Pro plugin (WP Manage Ninja) version 3.1.12 and earlier. Administrators and site owners who have not upgraded to 3.1.13 or later are exposed to this escalation risk. The plugin is commonly used in WordPress installations backing customer relationship management workflows. The CVSS score of 7.2 reflects a medium‑high severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, indicating a lower publicly observed exploitation probability at present. Nonetheless, the lack of official exploitation reports does not diminish the need for timely remediation, as the flaw directly impacts role‑based access control within the WordPress ecosystem.
Affected Systems
The WordPress FluentCRM Pro plugin (WP Manage Ninja) versions up to and including 3.1.12 are affected. Site owners using one or more installations of these plugin versions should evaluate their current WordPress role configurations.
Risk and Exploitability
Assessment shows that the vulnerability is exploitable by users with editor or higher privileges in the WordPress environment. The attack requires the attacker to authenticate as an editor and then use the plugin’s API to create or reassign capabilities. There is no documented requirement for network‑level exploitation, and the source code indicates no remote code execution is necessary. Given the medium‑high CVSS, the risk remains significant and remediation should be prioritized.
OpenCVE Enrichment