Unauthorized Data Modification in Devs CRM Plugin for WordPress
CVE-2025-13093
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 December 2025
What is CVE-2025-13093?
The Devs CRM plugin for WordPress contains a vulnerability that allows unauthenticated users to perform unauthorized data modifications via the '/wp-json/devs-crm/v1/bulk-update' REST API endpoint. This issue arises from a missing capability check, which directly enables attackers to maliciously alter lead tags within the system. All versions of the plugin up to and including 1.1.8 are affected, posing potential risks for data integrity and security for users managing tasks, attendance, and teams.
Affected Version(s)
Devs CRM β Manage tasks, attendance and teams all together * <= 1.1.8
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Athiwat Tiprasaharn