Unauthorized Data Modification in Devs CRM Plugin for WordPress
CVE-2025-13093
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 December 2025
What is CVE-2025-13093?
The Devs CRM plugin for WordPress contains a vulnerability that allows unauthenticated users to perform unauthorized data modifications via the '/wp-json/devs-crm/v1/bulk-update' REST API endpoint. This issue arises from a missing capability check, which directly enables attackers to maliciously alter lead tags within the system. All versions of the plugin up to and including 1.1.8 are affected, posing potential risks for data integrity and security for users managing tasks, attendance, and teams.
Affected Version(s)
Devs CRM β Manage tasks, attendance and teams all together * <= 1.1.8