Unauthorized Access Vulnerability in WP-CRM System Plugin for WordPress
CVE-2025-14854

5.4MEDIUM

What is CVE-2025-14854?

The WP-CRM System plugin for WordPress has a significant vulnerability that permits unauthorized access due to insufficient capability checks on key AJAX functions. Specifically, the wpcrm_get_email_recipients and wpcrm_system_ajax_task_change_status functions allow authenticated users with subscriber-level access or higher to retrieve sensitive CRM contact email addresses, leading to potential personal identifiable information (PII) exposure. Additionally, attackers can manipulate CRM task statuses, which can compromise the integrity of the CRM system. This flaw emphasizes the need for rigorous capability verifications to safeguard user data and maintain system integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

WP-CRM System – Manage Clients and Projects * <= 3.4.5

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Teerachai Somprasong
.