Missing Authorization Vulnerability in WP-CRM System by Mario Peshev
CVE-2025-62106
5.4MEDIUM
What is CVE-2025-62106?
The WP-CRM System developed by Mario Peshev contains a missing authorization vulnerability that allows attackers to exploit incorrectly configured access control levels. This issue can lead to unauthorized actions on behalf of the users, particularly affecting versions up to 3.4.5. It's crucial for website owners using this plugin to review their access control settings and implement relevant patches to secure their systems against potential exploits.
Affected Version(s)
WP-CRM System 0 <= 3.4.5