Description
The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the storeInfo function. This makes it possible for unauthenticated attackers to modify the plugin's Zoho CRM integration settings, replacing the configured data center, client ID, client secret, and user email credentials with attacker-controlled values via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Published: 2026-07-18
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The W3SC Elementor to Zoho CRM plugin allows a CSRF attack because the storeInfo function lacks or misapplies nonce validation. An attacker who can trick a site administrator into clicking a crafted link can replace the plugin’s data center, client ID, client secret, and user email credentials with values of the attacker’s choosing. This does not provide arbitrary code execution but allows the attacker to hijack the integration, potentially exposing sensitive data and allowing further abuse of the Zoho CRM account.

Affected Systems

The affected product is the WordPress plugin "W3SC Elementor to Zoho CRM" by W3SCloud. All releases through and including version 2.2.0 are vulnerable, regardless of the WordPress core or theme.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of being exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires social engineering of an administrator to trigger a forged request; no local or remote code execution prerequisites exist.

Generated by OpenCVE AI on July 30, 2026 at 23:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the W3SC Elementor to Zoho CRM plugin to the newest available version that corrects the nonce validation flaw.
  • Ensure that the WordPress installation keeps all plugins updated and runs a current version of WordPress to reduce overall attack surface.
  • If a patch is unavailable, disable the plugin’s settings page or restrict its access to trusted administrators only.

Generated by OpenCVE AI on July 30, 2026 at 23:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared W3scloud
W3scloud w3sc Elementor To Zoho Crm
Wordpress
Wordpress wordpress
Vendors & Products W3scloud
W3scloud w3sc Elementor To Zoho Crm
Wordpress
Wordpress wordpress

Wed, 22 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 18 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incorrect nonce validation on the storeInfo function. This makes it possible for unauthenticated attackers to modify the plugin's Zoho CRM integration settings, replacing the configured data center, client ID, client secret, and user email credentials with attacker-controlled values via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Title W3SC Elementor to Zoho CRM <= 2.2.0 - Cross-Site Request Forgery to Settings Update
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

W3scloud W3sc Elementor To Zoho Crm
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-22T16:09:10.179Z

Reserved: 2026-05-27T17:26:17.005Z

Link: CVE-2026-9734

cve-icon Vulnrichment

Updated: 2026-07-22T16:09:03.948Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:30:08Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)