Impact
The W3SC Elementor to Zoho CRM plugin allows a CSRF attack because the storeInfo function lacks or misapplies nonce validation. An attacker who can trick a site administrator into clicking a crafted link can replace the plugin’s data center, client ID, client secret, and user email credentials with values of the attacker’s choosing. This does not provide arbitrary code execution but allows the attacker to hijack the integration, potentially exposing sensitive data and allowing further abuse of the Zoho CRM account.
Affected Systems
The affected product is the WordPress plugin "W3SC Elementor to Zoho CRM" by W3SCloud. All releases through and including version 2.2.0 are vulnerable, regardless of the WordPress core or theme.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of being exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires social engineering of an administrator to trigger a forged request; no local or remote code execution prerequisites exist.
OpenCVE Enrichment